# Exploit Title : LiteManager 4.5.0 - 'romservice' Unquoted Serive Path # Date : 2019-10-15 # Exploit Author : Cakes # Vendor: LiteManager Team # Version : LiteManager 4.5.0 # Software: http://html.tucows.com/preview/1594042/LiteManager-Free?q=remote+support # Tested on Windows 10 # CVE : N/A c:\>sc qc romservice [SC] QueryServiceConfig SUCCESS SERVICE_NAME: romservice TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : C:\Program Files (x86)\LiteManagerFree - Server\ROMServer.exe LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : LiteManagerTeam LiteManager DEPENDENCIES : SERVICE_START_NAME : LocalSystem