TotalAV Unquoted Service Path Vulnerability Allowing SYSTEM Privilege Escalation
Vulnerability
A vulnerability exists in TotalAV version 5.15.69, specifically within the PC Security Management Service, PC Security Management Monitoring Service, and Anti-Malware SDK Protected Service. These services, all running with LocalSystem privileges, contain an unquoted service path vulnerability. This flaw allows attackers to place malicious executables in certain unquoted path segments, potentially leading to SYSTEM-level access by exploiting the service path configuration.
Impact
Exploitation of this vulnerability could allow a user to gain SYSTEM privileges on the affected machine.
Reproduction
The vulnerability can be reproduced by placing an executable in the unquoted path segments of the affected services. Once the executable is placed, it can be executed with SYSTEM privileges, taking advantage of the unquoted service path vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
