Security
Headlines
HeadlinesLatestCVEs

Headline

IOTransfer 4 Unquoted Service Path

IOTransfer version 4 suffers from an unquoted service path vulnerability.

Packet Storm
#vulnerability#windows#microsoft#php#auth
# Exploit Title: IOTransfer V4 - Unquoted Service Path# Exploit Author: BLAY ABU SAFIAN (Inveteck Global)# Discovery Date: 2022-28-07# Vendor Homepage: http://www.iobit.com/en/index.php# Software Link: https://iotransfer.itopvpn.com/download/# Tested Version: V4# Vulnerability Type: Unquoted Service Path# Tested on OS: Microsoft Windows Server 2019 Standard Evaluation CVE-2022-37197# Step to discover Unquoted Service Path:C:\>wmic service get name,displayname,pathname,startmode |findstr /i "auto" |findstr /i /v "c:\windows\\" |findstr /i /v """IOTransfer Updater IOTUpdaterSvc C:\Program Files (x86)\IOTransfer\Updater\IOTUpdater.exe                      AutoC:\>sc qc IOTUpdaterSvc[SC] QueryServiceConfig SUCCESSSERVICE_NAME: IOTUpdaterSvc        TYPE : 10 WIN32_OWN_PROCESS        START_TYPE : 2 AUTO_START        ERROR_CONTROL : 1 NORMAL        BINARY_PATH_NAME : C:\Program Files (x86)\IOTransfer\Updater\IOTUpdater.exeLOAD_ORDER_GROUP :        TAG : 0        DISPLAY_NAME : IOTransfer Updater        DEPENDENCIES :        SERVICE_START_NAME : LocalSystemC:\>systeminfoOS Name: Microsoft Windows Server 2019 Standard EvaluationOS Version: 10.0.17763 N/A Build 17763OS Manufacturer: Microsoft Corporation

Related news

CVE-2022-37197: Offensive Security’s Exploit Database Archive

IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

Packet Storm: Latest News

CUPS IPP Attributes LAN Remote Code Execution