PT-2019-10051 · Winmagic · Winmagic Securedoc Disk Encryption
Published
2019-04-08
·
Updated
2019-04-24
·
CVE-2018-20341
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WINMAGIC SecureDoc Disk Encryption software versions prior to 8.3
Description:
The issue allows an attacker to execute arbitrary code on a target system due to an Unquoted Service Path vulnerability. This occurs when the path to the application binary does not contain quotes, causing Windows to search for and potentially execute the binary in every folder of the specified path until it finds the executable.
Recommendations:
For versions prior to 8.3, update to version 8.3 or later to resolve the issue. As a temporary workaround, consider enclosing the executable path in quote tags to prevent Windows from searching for the binary in multiple folders.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winmagic Securedoc Disk Encryption