Sanyo Denki Sanups Software Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in SANUPS SOFTWARE provided by SANYO DENKI CO., LTD., where Windows services are registered with unquoted file paths. This issue affects SANUPS SOFTWARE STANDALONE versions 1.0.1 to 1.1.4, as well as SANUPS SOFTWARE versions 2.0.0 to 2.0.2 and 1.0.0 to 1.1.4. A user with write permission on the root directory of the system drive could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. The vulnerability arises because the installation path can be manipulated to execute malicious payloads as a service.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with SYSTEM privileges, allowing for significant control over the affected system.

Reproduction

To reproduce this vulnerability, install an affected version of SANUPS SOFTWARE on a system where the installation path contains spaces. Once the software is installed, place a malicious executable in the path where the service executable is located. The service will execute the malicious program with elevated privileges.

Remediation

Users are advised to update SANUPS SOFTWARE STANDALONE to version 1.1.5 or SANUPS SOFTWARE to version 2.0.3. For SANUPS SOFTWARE versions 1.0.0 to 1.1.4, upgrade to version 3.0.1. Instructions for downloading the updated versions are available on the SANYO DENKI website.

Added: Mar 25, 2026, 6:20 AM
Updated: Mar 25, 2026, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.2
remediation
0.0
relevance
4.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.