ITeC ITeCProteccioAppServer Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in the ITeC ITeCProteccioAppServer due to an unquoted service path. This flaw allows local attackers to execute arbitrary code with elevated system privileges. By placing a malicious executable in the service path, attackers can gain elevated access when the service is restarted or the system is rebooted.

Impact

Exploitation of this vulnerability allows for unauthorized code execution with elevated privileges on the system.

Reproduction

To reproduce this vulnerability, a local attacker must insert a malicious executable into the unquoted service path of the ITeCProteccioAppServer. This can be done by placing the executable in a location that the service will access. Once the executable is in place, the service can be restarted or the system can be rebooted, at which point the malicious code will be executed with elevated privileges.

Added: Jan 14, 2026, 12:23 AM
Updated: Jan 14, 2026, 12:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.2
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.