Unquoted Windows Search Path Vulnerability in Unisys s-Par
CVE-2017-5873

6.7MEDIUM

Key Information:

Vendor

Unisys

Vendor
CVE Published:
11 April 2017

What is CVE-2017-5873?

The unquoted Windows search path vulnerability in Unisys s-Par prior to version 4.4.20 allows local users to escalate privileges. This occurs when an attacker places a Trojan horse executable in the %SYSTEMDRIVE% directory, which the system fails to properly execute due to unquoted paths. Exploiting this vulnerability can lead to unauthorized access and manipulation of system-level permissions, making it critical for users to ensure they are running updated versions and to implement stringent security practices.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.