Magic Mouse 2 Utilities Unquoted Service Path Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability exists in Magic Mouse 2 Utilities version 2.20 due to an unquoted service path in its Windows service configuration. This flaw allows attackers to inject malicious executables and gain elevated system privileges by placing a harmful file in the service path.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of malicious files with elevated privileges, potentially allowing for significant system modifications or access.
Reproduction
The vulnerability can be reproduced by querying the service configuration for 'magicmouse2service' using the 'sc qc' command. This will reveal the unquoted service path, which can be exploited by placing a malicious executable in the specified directory.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
