Wise Care 365 Unquoted Service Path Vulnerability in WiseBootAssistant

Vulnerability

A unquoted service path vulnerability has been identified in Wise Care 365 version 5.6.7.568, specifically within the WiseBootAssistant service, which operates with LocalSystem privileges. This vulnerability allows attackers to place a malicious executable in the service path, which would then be executed with elevated system rights when the service is restarted.

Impact

Exploitation of this vulnerability allows for unauthorized execution of code with elevated privileges, potentially leading to full system compromise.

Reproduction

The vulnerability can be reproduced by inserting a malicious executable into the unquoted service path of the WiseBootAssistant service. This can be done by first identifying the service path using the Windows Management Instrumentation Command-line (WMIC) tool. Once the service path is known, the malicious executable can be placed in that location. When the service or system is restarted, the malicious executable will run with elevated privileges.

Added: Jan 16, 2026, 12:37 AM
Updated: Jan 16, 2026, 12:37 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
4.6
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.