Motorola Device Manager Unquoted Service Path Vulnerability in PST Service Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Motorola Device Manager versions 2.4.5 and 2.5.4, specifically within the PST Service. This vulnerability is an unquoted service path issue that could allow local users to execute arbitrary code. The flaw arises because the service path in 'ForwardDaemon.exe' is not properly quoted, enabling potential injection of malicious code that could be executed with elevated system privileges when the service starts.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with elevated privileges on the system.

Reproduction

The vulnerability can be reproduced by using the Windows Management Instrumentation Command-line (WMIC) tool to query service details. Look for the 'PST Service' which will reveal the unquoted path of 'ForwardDaemon.exe'. This unquoted path can then be exploited to execute arbitrary code with elevated privileges.

Added: Jan 27, 2026, 7:31 PM
Updated: Jan 27, 2026, 7:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.8
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.