Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50935. PoCs published by Ismael Nava.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in the FLAME II HSPA USB MODEM Service. The vulnerability allows local privilege escalation due to the service path containing spaces and not being enclosed in quotes.
Description
Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in the FLAME II HSPA USB MODEM Service. The vulnerability allows local privilege escalation due to the service path containing spaces and not being enclosed in quotes.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H