PT-2017-16824 · Waves · Waves Maxxaudio
Juz P3Nt3$T
·
Published
2017-07-26
·
Updated
2019-10-03
·
CVE-2017-6005
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Waves MaxxAudio version 1.1.6.0
Description
The issue concerns a vulnerability known as Unquoted Service Path in the WavesSysSvc Windows service. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Recommendations
For Waves MaxxAudio version 1.1.6.0, consider updating the service to a version that quotes the service path to prevent exploitation. Alternatively, as a temporary workaround, consider restricting access to the WavesSysSvc service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Waves Maxxaudio