CVE-2017-7180

HIGH

Net Monitor for Employees Pro <5.3.4 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-7180. PoCs published by Saeid Atabaki.

AI-analyzed exploit summary This advisory describes an unquoted service path vulnerability in Net Monitor for Employees Pro <= 5.3.4, where the service path contains spaces and lacks quotes, allowing local privilege escalation via executable placement in the path. The writeup includes technical details such as service configuration and exploitation steps.

Description

Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.

Exploits (1)

exploitdb WRITEUP
by Saeid Atabaki · textlocalwindows
https://www.exploit-db.com/exploits/42141

This advisory describes an unquoted service path vulnerability in Net Monitor for Employees Pro <= 5.3.4, where the service path contains spaces and lacks quotes, allowing local privilege escalation via executable placement in the path. The writeup includes technical details such as service configuration and exploitation steps.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Net Monitor for Employees Pro <= 5.3.4
Auth required
Prerequisites: Local access to the system · Ability to place an executable in the unquoted service path
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42141/

Scores

CVSS v3 7.3
EPSS 0.0105
EPSS Percentile 59.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
eduiq/net_monitor_for_employees < 5.3.4
Published Jun 08, 2017
Tracked Since Feb 18, 2026