mickem / nscp

NSClient++
http://nsclient.org
GNU General Public License v2.0
233 stars 91 forks source link

nsclient++.exe / Unquoted Service Path Enumeration #797

Open ca-py-ba-ra opened 1 year ago

ca-py-ba-ra commented 1 year ago

On Windows, the service NSClientpp is missing quotation marks: C:\Program Files\NSClient++\nsclient++.exe

For this reason, the service is vulnerable to "Unquoted Service Path Enumeration".

More information about the vulnerability can be found here: https://attack.mitre.org/techniques/T1574/009/