PT-2017-16824 · Waves · Waves Maxxaudio

Juz P3Nt3$T

·

Published

2017-07-26

·

Updated

2019-10-03

·

CVE-2017-6005

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Waves MaxxAudio version 1.1.6.0
Description The issue concerns a vulnerability known as Unquoted Service Path in the WavesSysSvc Windows service. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Recommendations For Waves MaxxAudio version 1.1.6.0, consider updating the service to a version that quotes the service path to prevent exploitation. Alternatively, as a temporary workaround, consider restricting access to the WavesSysSvc service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-6005

Affected Products

Waves Maxxaudio