Avast secureline 5.5.522.0 secureline unquoted service path Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-03-25 |
Type : local |
Platform : windows
This exploit / vulnerability Avast secureline 5.5.522.0 secureline unquoted service path is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
# Discovery by: Roberto Piña
# Discovery Date: 2020-03-24
# Vendor Homepage:https://www.avast.com/
# Software Link :https://www.avast.com/es-mx/download-thank-you.php?product=SLN&locale=es-mx
# Tested Version: 5.5.522.0
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 8.1 Single Language x32 es
# Step to discover Unquoted Service Path:
C:\>wmic service get name, pathname, displayname, startmode | findstr "Auto" | f
indstr /i /v "C:\Windows\\" | findstr /i "Avast SecureLine" | findstr /i /v """
Avast SecureLine
SecureLine C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
Auto
# Exploit:
# A successful attempt would require the local user to be able to insert their code in the system root path
# undetected by the OS or other security applications where it could potentially be executed during
# application startup or reboot. If successful, the local user's code would execute with the elevated
# privileges of the application.
Avast secureline 5.5.522.0 secureline unquoted service path