Menu

#2737 Unquoted Service Path Enumeration vulnerability in snmpd on windows

windows
open
nobody
None
5
2016-07-29
2016-07-29
Darren Long
No

When "snmpd.exe -register" is invoked on Windows platforms the ImagePath shown in the registry editor for the service is not quoted. Further info on this class of vulnerabilities can be seen here:
http://isc.sans.edu/diary.html?storyid=14464
http://cwe.mitre.org/data/definitions/428.html
http://www.commonexploits.com/?p=658

This was observed in Net-SNMP v5.7.3

Discussion


Log in to post a comment.

MongoDB Logo MongoDB