Untrusted search path in Cobian Backup - #VU60927
Published: March 1, 2022
Cobian Backup
Luis Cobian
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to an unquoted service path flaw in "C:\Program Files (x86)\Cobian Backup 11\cbService.exe". A local user can use a specially crafted file and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.