Unquoted Service Path Vulnerability in WAB-MAT by Elecom
CVE-2023-22282
7.3HIGH
What is CVE-2023-22282?
The WAB-MAT software by Elecom, in versions 5.0.0.8 and earlier, presents a security vulnerability that arises from an unquoted file path in its service configuration. This flaw allows an attacker to exploit the unquoted service path by placing a malicious executable in a directory with spaces in its name. When the Windows service attempts to start the application, it may inadvertently execute the malicious file, resulting in privilege escalation under the Windows service's context. Users of WAB-MAT should take immediate steps to secure their installations and monitor for potential threats.
Affected Version(s)
WAB-MAT Ver.5.0.0.8 and earlier