Skip to content

Microsoft Vulnerability with icinga-service. #298

@drapiti

Description

@drapiti

Our security department has identitified a potential vulnerbility with the default installation of the icingapowershell service.

"The remote Windows host has at least one service installed that uses an unquoted service path, which contains at least one whitespace. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service."

The second part is ok, it's the first part which should be quoted.

image

Cheers.

Metadata

Metadata

Assignees

Labels

SecurityA security flaw within the Icinga PowerShell Framework

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions