impulse-xdr icon indicating copy to clipboard operation
impulse-xdr copied to clipboard

Unquoted service path in Windows sensors

Open l4rm4nd opened this issue 1 year ago • 1 comments

Windows sensors will install a new service called impulse-agentd.

This service is executing the nssm.exe binary. However, the service does not quote the service path. This may lead to a Windows privilege escalation if an attacker would be able to create a malicious file located at C:\Program.exe. This is usually not possible by a low privileged user account.

Nonetheless, I recommend quoting the service path for security best practices.

image

l4rm4nd avatar Mar 28 '24 01:03 l4rm4nd

Thanks, will be fixed in the next release.

bgenev avatar Mar 29 '24 07:03 bgenev