When running a program from a command prompt on a system with Raccine installed, yara64.exe will be attempted to be executed from the current directory. This can allow for unexpected code execution on a system with Raccine installed.
Steps to reproduce:
Make a directory called c:\tmp and go there in a command prompt.
Copy c:\windows\system32\calc.exe to c:\tmp\yara64.exe
In the CMD prompt in the c:\tmp directory, type: powershell
Actual results:
calc.exe spawns
Expected results:
yara64.exe should only be executed from the known directory where it is installed. Not from the current directory, nor from other directories that happen to be in the PATH.
When running a program from a command prompt on a system with Raccine installed, yara64.exe will be attempted to be executed from the current directory. This can allow for unexpected code execution on a system with Raccine installed.
Steps to reproduce:
Actual results: calc.exe spawns
Expected results: yara64.exe should only be executed from the known directory where it is installed. Not from the current directory, nor from other directories that happen to be in the PATH.