← volver
CVE-2020-36927

DiskPulse 13.6.14 - Unquoted Service Path

CVSS 8.5 HIGHEPSS 0.2%CWE-428
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject malicious executables and escalate privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Diskpulse · DiskPulse

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →