Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block…
mitre·CWE-428·Published 2017-06-08
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.
Net Monitor for Employees Pro hasta la versión 5.3.4 presenta una ruta de servicio sin comillas, que permite omitir la función de seguridad de su objetivo de diseño documentado "Block applications". El atacante local debe tener privilegios para escribir en el archivo program.exe en un directorio protegido, como el directorio %SYSTEMDRIVE%, y por lo tanto el problema no se interpreta como una escalada directa de privilegios. Sin embargo, el atacante local podría tener el objetivo de ejecutar program.exe aunque program.exe sea una aplicación bloqueada.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 6.9 | 3.4 | 10.0 | AV:L/AC:M/Au:N/C:C/I:C/A:C |
| 3.1 | Primary | NVD | 7.3 | 1.3 | 5.9 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |