PT-2019-10051 · Winmagic · Winmagic Securedoc Disk Encryption

Published

2019-04-08

·

Updated

2019-04-24

·

CVE-2018-20341

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WINMAGIC SecureDoc Disk Encryption software versions prior to 8.3
Description: The issue allows an attacker to execute arbitrary code on a target system due to an Unquoted Service Path vulnerability. This occurs when the path to the application binary does not contain quotes, causing Windows to search for and potentially execute the binary in every folder of the specified path until it finds the executable.
Recommendations: For versions prior to 8.3, update to version 8.3 or later to resolve the issue. As a temporary workaround, consider enclosing the executable path in quote tags to prevent Windows from searching for the binary in multiple folders.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20341

Affected Products

Winmagic Securedoc Disk Encryption