Unquoted Windows Search Path Vulnerability in Microsoft Antispyware
CVE-2005-2940
Currently unrated
What is CVE-2005-2940?
The unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) poses a significant risk, as it enables local users to gain elevated privileges through a maliciously crafted file named 'program.exe' placed in the C: directory. This vulnerability affects several executable components within the software, including GIANTAntiSpywareMain.exe, gcASNotice.exe, gcasServ.exe, gcasSWUpdater.exe, and GIANTAntiSpywareUpdater.exe, potentially allowing unauthorized access and manipulation of system resources.