Description
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26731 | An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service. |
References
History
No history.
Subscriptions
Toshiba
Subscribe
Hd-ma10ts
Subscribe
Hd-ma10ty
Subscribe
Hd-ma20ts
Subscribe
Hd-ma20ty
Subscribe
Hd-ma30ts
Subscribe
Hd-ma30ty
Subscribe
Hd-mb10ts
Subscribe
Hd-mb10ty
Subscribe
Hd-mb20ts
Subscribe
Hd-mb20ty
Subscribe
Hd-mb30ts
Subscribe
Hd-mb30ty
Subscribe
Hd-sa50gk
Subscribe
Hd-sa50gs
Subscribe
Hd-sb10tk
Subscribe
Hd-sb10ts
Subscribe
Hd-sb50gk
Subscribe
Hd-sb50gs
Subscribe
Password Tool For Windows
Subscribe
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-04T08:30:24.635Z
Reserved: 2020-01-06T00:00:00.000Z
Link: CVE-2020-5569
No data.
Status : Modified
Published: 2020-04-20T08:15:15.130
Modified: 2024-11-21T05:34:17.387
Link: CVE-2020-5569
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD