CVE-2021-47886
7.8Fyrolabs LLC · Pingzapper
Pingzapper 2.3.1 is vulnerable to an unquoted service path issue in the PingzapperSvc service, which could allow a local attacker to execute arbitrary code and escalate privileges.
Executive summary
A local privilege escalation vulnerability exists in Pingzapper 2.3.1 due to an unquoted service path, posing a significant risk of arbitrary code execution on affected Windows systems.
Vulnerability
The application utilizes an unquoted service path for the PingzapperSvc service, specifically C:\Program Files (x86)\Pingzapper\PZService.exe. This flaw allows a local, authenticated attacker to place a malicious executable in a directory that the service path resolves to, leading to privilege escalation when the service executes.
Business impact
Successful exploitation of this vulnerability allows a local attacker to execute arbitrary code with SYSTEM level privileges. This compromises the integrity and confidentiality of the host operating system, potentially leading to full system takeover, unauthorized access to sensitive data, and the deployment of persistent malware. Given the CVSS score of 7.8, this represents a high-severity risk that requires immediate attention for all deployments running the affected version.
Remediation
Immediate Action: Upgrade to the latest available version of Pingzapper provided by Fyrolabs LLC to ensure the service path is properly quoted or remediated.
Proactive Monitoring: Audit Windows services for unquoted service paths and monitor system logs for unusual process creation events originating from the service control manager.
Compensating Controls: Restrict write permissions on the directory paths associated with services to prevent unauthorized users from placing malicious executables in the path hierarchy.
Exploitation status
Public Exploit Available: Yes, a functional local exploit is documented on Exploit-DB (EDB-ID 49626).
Analyst recommendation
The presence of a public exploit and the potential for full system compromise via privilege escalation necessitate urgent remediation. Organizations should verify their current version of Pingzapper and apply the vendor-supplied update immediately. If an update is not immediately feasible, system administrators should manually ensure that service paths are correctly quoted in the Windows Registry to mitigate this attack vector.
Sources
Originally found and disclosed by Brian Rodriguez, per the CVE Program record.
- ExploitDB-49626 Exploit / PoC
- Vendor Homepage
- Software Download Page
- VulnCheck Advisory: Pingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service Path Third-party advisory