Wise Care 365
cpe:2.3:a:wisecleaner:wise_care_365:*:*:*:*:*:*:*
- 5.6.7.568
A unquoted service path vulnerability has been identified in Wise Care 365 version 5.6.7.568, specifically within the WiseBootAssistant service, which operates with LocalSystem privileges. This vulnerability allows attackers to place a malicious executable in the service path, which would then be executed with elevated system rights when the service is restarted.
Exploitation of this vulnerability allows for unauthorized execution of code with elevated privileges, potentially leading to full system compromise.
The vulnerability can be reproduced by inserting a malicious executable into the unquoted service path of the WiseBootAssistant service. This can be done by first identifying the service path using the Windows Management Instrumentation Command-line (WMIC) tool. Once the service path is known, the malicious executable can be placed in that location. When the service or system is restarted, the malicious executable will run with elevated privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.