WorkgroupMail Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A vulnerability exists in WorkgroupMail version 7.5.1 due to an unquoted service path in its Windows service configuration. This flaw allows local attackers to execute arbitrary code by injecting malicious executables into the unquoted binary path. These executables would be executed with LocalSystem privileges when the service starts.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code with LocalSystem privileges.
Reproduction
The vulnerability can be reproduced by injecting a malicious executable into the unquoted service path of the WorkgroupMail Windows service. The injected executable will be executed with LocalSystem privileges when the service is started.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
