Unquoted Service Path Vulnerability in WAB-MAT by Elecom
CVE-2023-22282

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
11 April 2023

Summary

The WAB-MAT software by Elecom, in versions 5.0.0.8 and earlier, presents a security vulnerability that arises from an unquoted file path in its service configuration. This flaw allows an attacker to exploit the unquoted service path by placing a malicious executable in a directory with spaces in its name. When the Windows service attempts to start the application, it may inadvertently execute the malicious file, resulting in privilege escalation under the Windows service's context. Users of WAB-MAT should take immediate steps to secure their installations and monitor for potential threats.

Affected Version(s)

WAB-MAT Ver.5.0.0.8 and earlier

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.