Menu

#66 Unquoted Service CNTLM

v0.93 show-stopper
open
nobody
5
2014-07-15
2014-07-15
No

Dear cntlm maintainers,

I am using CNTLM Version 0.92.3. There is a possible Unquoted Service Path Vulnerability in HKLM\SYSTEM\CurrentControlSet\services and path C:\Program Files (x86)\Cntlm\cygrunsrv.exe. This could potentially allow an authorized but non privileged local user to execute arbitrary code with elevated privileges on the system.

Discussion


Log in to post a comment.