SYSTEM privilege escalation via unquoted service path
Published Apr 23, 2024 · Updated Nov 22, 2024
Unquoted service path handling in TerraTec DMX 6fire 24/96 ControlPanel allows local users to execute code with SYSTEM privileges. The automatically started ttdmx6firesvc service runs as LocalSystem but registers its executable under Program Files without surrounding quotation marks, allowing Windows to select an attacker-placed executable from a searched parent path. A local user needs write access to such a path; the CNA names DMX 6Fire USB 1.23.0.02, while CISA maps the record to the 24/96 ControlPanel.
Summary
What happened
Unquoted service path handling in TerraTec DMX 6fire 24/96 ControlPanel allows local users to execute code with SYSTEM privileges. The automatically started ttdmx6firesvc service runs as LocalSystem but registers its executable under Program Files without surrounding quotation marks, allowing Windows to select an attacker-placed executable from a searched parent path. A local user needs write access to such a path; the CNA names DMX 6Fire USB 1.23.0.02, while CISA maps the record to the 24/96 ControlPanel.
The record
- CVE
- CVE-2024-31804
- Published
- Apr 23, 2024
- Updated
- Nov 22, 2024
- Vendor
- TerraTec Electronic GmbH
- Product
- TerraTec DMX 6fire 24/96 ControlPanel
- Classifications
- CWE-428, T1574.009
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Apr 23, 2024CVE publishedPublication date reported by the CVE source.
- Nov 22, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=*
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Terratec dmx_6fire USB - Unquoted Service Pathproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo