{"id":56233,"date":"2024-04-12T19:29:47","date_gmt":"2024-04-12T15:29:47","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178036\/terratecdmx6fireusb123002-unquotedpath.txt"},"modified":"2024-04-12T19:29:47","modified_gmt":"2024-04-12T15:29:47","slug":"terratec-dmx_6fire-usb-1-23-0-02-unquoted-service-path","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/terratec-dmx_6fire-usb-1-23-0-02-unquoted-service-path\/","title":{"rendered":"Terratec dmx_6fire USB 1.23.0.02 Unquoted Service Path"},"content":{"rendered":"<dl id=\"F178036\" class=\"file first\" readability=\"-1.2586206896552\">\n<dt><a class=\"ico text-plain\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/178036\/terratecdmx6fireusb123002-unquotedpath.txt\" title=\"Size: 1.2 KB\" target=\"_blank\" rel=\"noopener\"><strong>Terratec dmx_6fire USB 1.23.0.02 Unquoted Service Path<\/strong><\/a><\/dt>\n<dd class=\"datetime\">Posted <a href=\"https:\/\/packetstormsecurity.com\/files\/date\/2024-04-12\/\" title=\"14:46:52 UTC\" target=\"_blank\" rel=\"noopener\">Apr 12, 2024<\/a><\/dd>\n<dd class=\"refer\">Authored by <a href=\"https:\/\/packetstormsecurity.com\/files\/author\/17122\/\" class=\"person\" target=\"_blank\" rel=\"noopener\">Joseph Kwabena Fiagbor<\/a><\/dd>\n<dd class=\"detail\" readability=\"-1\">\n<p>Terratec dmx_6fire USB version 1.23.0.02 suffers from an unquoted service path vulnerability.<\/p>\n<\/dd>\n<dd class=\"tags\"><span>tags<\/span> | <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/exploit\" target=\"_blank\" rel=\"noopener\">exploit<\/a><\/dd>\n<dd class=\"cve\"><span>advisories<\/span> | <a href=\"https:\/\/packetstormsecurity.com\/files\/cve\/CVE-2024-31804\" target=\"_blank\" rel=\"noopener\">CVE-2024-31804<\/a><\/dd>\n<dd class=\"md5\"><span>SHA-256<\/span> | <code>3b1ae38d17de2b6bb05d853af820ee9f6f5e2f2251357f5de9240f209b72112f<\/code><\/dd>\n<dd class=\"act-links\"><a href=\"https:\/\/packetstormsecurity.com\/files\/download\/178036\/terratecdmx6fireusb123002-unquotedpath.txt\" title=\"Size: 1.2 KB\" rel=\"nofollow noopener\" target=\"_blank\">Download<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/favorite\/178036\/\" class=\"fav\" rel=\"nofollow noopener\" target=\"_blank\">Favorite<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/178036\/Terratec-dmx_6fire-USB-1.23.0.02-Unquoted-Service-Path.html\" target=\"_blank\" rel=\"noopener\">View<\/a><\/dd>\n<\/dl>\n<div class=\"src\" readability=\"9.792899408284\">\n<pre readability=\"7.5\"><code readability=\"9\"># Exploit Title: Terratec dmx_6fire USB - Unquoted Service Path<br># Google Dork: null<br># Date: 4\/10\/2024<br># Exploit Author: Joseph Kwabena Fiagbor<br># Vendor Homepage: https:\/\/dmx-6fire-24-96-controlpanel.software.informer.com\/download\/<br># Software Link:<br># Version: v.1.23.0.02<br># Tested on: windows 7-11<br># CVE : CVE-2024-31804<p>1. Description:<\/p><p>The Terratec dmx_6fire usb installs as a service with an unquoted service<br>path running<br>with SYSTEM privileges.<br>This could potentially allow an authorized but non-privileged local<br>user to execute arbitrary code with elevated privileges on the system.<\/p><p>2. Proof<\/p><p>&gt; C:\\Users\\Astra&gt;sc qc \"ttdmx6firesvc\"<br>&gt; {SC] QueryServiceConfig SUCCESS<br>&gt;<br>&gt; SERVICE_NAME: ttdmx6firesvc<br>&gt; TYPE : 10 WIN32_OWN_PROCESS<br>&gt; START_TYPE : 2 AUTO_START<br>&gt; ERROR_CONTROL : 1 NORMAL<br>&gt; BINARY_PATH_NAME : C:\\Program Files\\TerraTec\\DMX6FireUSB\\ttdmx6firesvc.exe -service<br>&gt; LOAD_ORDER_GROUP : PlugPlay<br>&gt; TAG : 0<br>&gt; DISPLAY_NAME : DMX6Fire Control<br>&gt; DEPENDENCIES : eventlog<br>&gt; : PlugPlay<br>&gt; SERVICE_START_NAME : LocalSystem<br>&gt;<br>&gt;<\/p><\/code><\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Terratec dmx_6fire USB 1.23.0.02 Unquoted Service Path Posted Apr 12, 2024 Authored by Joseph Kwabena Fiagbor Terratec dmx_6fire USB version 1.23.0.02 suffers from an unquoted service path vulnerability. tags | exploit advisories | CVE-2024-31804 SHA-256 | 3b1ae38d17de2b6bb05d853af820ee9f6f5e2f2251357f5de9240f209b72112f Download | Favorite | View # Exploit Title: Terratec dmx_6fire USB &#8211; Unquoted Service Path# Google Dork: null# &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56233","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56233"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56233\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}