Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-7180. PoCs published by Saeid Atabaki.
AI-analyzed exploit summary This advisory describes an unquoted service path vulnerability in Net Monitor for Employees Pro <= 5.3.4, where the service path contains spaces and lacks quotes, allowing local privilege escalation via executable placement in the path. The writeup includes technical details such as service configuration and exploitation steps.
Description
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.
Exploits (1)
This advisory describes an unquoted service path vulnerability in Net Monitor for Employees Pro <= 5.3.4, where the service path contains spaces and lacks quotes, allowing local privilege escalation via executable placement in the path. The writeup includes technical details such as service configuration and exploitation steps.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H