DiskBoss Service Unquoted Service Path Vulnerability Allowing Elevated Privileges

Vulnerability

A vulnerability exists in DiskBoss Service version 12.2.18 due to an unquoted service path in the binary path configuration. This flaw allows local attackers to execute code with elevated privileges. Exploitation involves placing malicious executables in locations that the unquoted path may reference, enabling attackers to gain system-level access when the service starts up.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution with elevated privileges, allowing a user to execute malicious payloads with system-level rights.

Reproduction

The vulnerability can be reproduced by installing DiskBoss Service version 12.2.18. After installation, the unquoted service path can be verified using the Windows Management Instrumentation Command-line (WMIC) tool. The service name 'DiskBoss Service' can be queried to reveal the unquoted binary path. Once the unquoted path is identified, malicious executables can be placed in a location that the service will reference, such as the Program Files directory. When the service is started, the malicious executables will be executed with elevated privileges.

Added: Jan 16, 2026, 7:43 PM
Updated: Jan 16, 2026, 7:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
4.8
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.