exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

eBeam Education Suite 2.5.0.9 Unquoted Service Path

eBeam Education Suite 2.5.0.9 Unquoted Service Path
Posted Mar 15, 2021
Authored by Luis Martinez

eBeam Education Suite version 2.5.0.9 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | 07a48d0a80b6e6fb6cffc7ab3242dea1c5592445f28a09fc4e95014cb6f08235

eBeam Education Suite 2.5.0.9 Unquoted Service Path

Change Mirror Download
# Exploit Title: eBeam education suite 2.5.0.9 - 'eBeam Device Service' Unquoted Service Path
# Discovery by: Luis Martinez
# Discovery Date: 2021-03-14
# Vendor Homepage: https://www.luidia.com
# Tested Version: 2.5.0.9
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 Pro x64 es

# Step to discover Unquoted Service Path:

C:\>wmic service get name, pathname, displayname, startmode | findstr /i "Auto" | findstr /i /v "C:\
Windows\\" | findstr /i "eBeam" | findstr /i /v """


eBeam Device Service eBeam Device Service C:\Program Files (x86)\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe Auto


# Service info:

C:\>sc qc "eBeam Device Service"
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: eBeam Device Service
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files (x86)\Luidia\eBeam Device Service\eBeamDeviceServiceMa
in.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : eBeam Device Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem

#Exploit:

A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.

Login or Register to add favorites

File Archive:

October 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    10 Files
  • 2
    Oct 2nd
    0 Files
  • 3
    Oct 3rd
    0 Files
  • 4
    Oct 4th
    0 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close