Honeywell WIN-PAK PRO
cpe:2.3:a:honeywell:win-pak:*:*:*:*:*:*:*
- 4.8
A unquoted service path vulnerability has been identified in Honeywell's Win-PACK Pro version 4.8, specifically within the GuardTourService. This vulnerability allows local users to execute code with elevated system privileges. The issue arises from the unquoted service path in 'C:\Program Files (x86)\WINPAKPRO\WP GuardTour Service.exe', which can be exploited to inject malicious code that executes during the service's startup.
Exploitation of this vulnerability could lead to unauthorized code execution with elevated privileges, allowing local users to execute malicious payloads that could be harmful to the system or network.
The vulnerability can be reproduced by inserting malicious code into the system root path, where it can remain undetected by the operating system or security applications. This code would then be executed during the startup of the GuardTourService, which runs with elevated privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.