Unquoted Service Path Vulnerabilities in Dell WMS Versions 1.1 and Prior

Unquoted Service Path Vulnerabilities in Dell WMS Versions 1.1 and Prior

CVE-2018-11063 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.

Learn more about our User Device Pen Test.