CVE-2021-47863
7.8MacPaw · Encrypto
MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its service configuration, potentially allowing local attackers to execute arbitrary code and escalate privileges on Windows.
Executive summary
A local privilege escalation vulnerability in MacPaw Encrypto 1.0.1 allows attackers to execute arbitrary code by exploiting an unquoted service path.
Vulnerability
The application utilizes an unquoted service path for the Encrypto Service, which is a common misconfiguration that allows a local user to place a malicious executable in the parent directory of the path. When the service restarts, the system executes the malicious file with LocalSystem privileges instead of the intended binary.
Business impact
Successful exploitation of this vulnerability leads to a full compromise of the affected Windows host. Because the service runs with LocalSystem privileges, an attacker can gain complete control over the operating system, bypass security controls, and access sensitive data. Given the CVSS score of 7.8, this represents a high-severity risk to business operations and data integrity.
Remediation
Immediate Action: Since no official patch is currently identified for this legacy version, administrators should restrict filesystem permissions on the installation directory to prevent unauthorized users from writing files to the path.
Proactive Monitoring: Monitor system logs for the creation of new, unexpected executable files within the C:\Program Files\ directory and review service startup events for anomalous behavior.
Compensating Controls: Implement endpoint security solutions that detect and block unauthorized modification of service binary paths or the execution of unsigned binaries in protected system directories.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exploit is available via the Exploit Database (EDB-ID: 49694).
Analyst recommendation
The presence of a publicly available exploit for this unquoted service path vulnerability necessitates immediate attention. Organizations should prioritize restricting folder permissions to prevent unauthorized file placement and evaluate the necessity of the software if a vendor-provided update remains unavailable. Failure to secure the service path allows for trivial privilege escalation, which could facilitate broader lateral movement within the network.
Sources
Originally found and disclosed by Ismael Nava, per the CVE Program record.
- ExploitDB-49694 Exploit / PoC
- MacPaw Encrypto Official Homepage
- VulnCheck Advisory: MacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path Third-party advisory