Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50808. PoCs published by Damian Semon Jr.
AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in CoolerMaster MasterPlus 1.8.5, where the service path lacks quotes, allowing potential privilege escalation via executable placement in a parent directory. The writeup includes steps to identify the vulnerability and exploit it by placing a malicious executable in the root of C:\.
Description
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.
Exploits (1)
This exploit describes an unquoted service path vulnerability in CoolerMaster MasterPlus 1.8.5, where the service path lacks quotes, allowing potential privilege escalation via executable placement in a parent directory. The writeup includes steps to identify the vulnerability and exploit it by placing a malicious executable in the root of C:\.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H