Unquoted Service Path Vulnerability in WAB-MAT by Elecom
CVE-2023-22282
7.3HIGH
Summary
The WAB-MAT software by Elecom, in versions 5.0.0.8 and earlier, presents a security vulnerability that arises from an unquoted file path in its service configuration. This flaw allows an attacker to exploit the unquoted service path by placing a malicious executable in a directory with spaces in its name. When the Windows service attempts to start the application, it may inadvertently execute the malicious file, resulting in privilege escalation under the Windows service's context. Users of WAB-MAT should take immediate steps to secure their installations and monitor for potential threats.
Affected Version(s)
WAB-MAT Ver.5.0.0.8 and earlier
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved