Magic Mouse 2 Utilities Unquoted Service Path Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in Magic Mouse 2 Utilities version 2.20 due to an unquoted service path in its Windows service configuration. This flaw allows attackers to inject malicious executables and gain elevated system privileges by placing a harmful file in the service path.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of malicious files with elevated privileges, potentially allowing for significant system modifications or access.

Reproduction

The vulnerability can be reproduced by querying the service configuration for 'magicmouse2service' using the 'sc qc' command. This will reveal the unquoted service path, which can be exploited by placing a malicious executable in the specified directory.

Added: Jan 25, 2026, 2:19 PM
Updated: Jan 25, 2026, 2:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.