First published: Sat Feb 28 2015(Updated: )
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Toshiba Bluetooth Wireless Device Driver | =9.10.27\(t\) | |
Microsoft Windows | ||
Toshiba Service Station | <=2.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0884 is classified as a local privilege escalation vulnerability.
To fix CVE-2015-0884, upgrade the Toshiba Bluetooth Stack to version 9.10.32(T) or later, and update the Toshiba Service Station to version 2.2.14 or later.
CVE-2015-0884 affects local users of Toshiba Bluetooth Stack versions prior to 9.10.32(T) and Toshiba Service Station versions before 2.2.14.
CVE-2015-0884 is caused by an unquoted Windows search path that allows local users to execute a Trojan horse application.
If you are using Toshiba Bluetooth Stack version 9.10.27(T) or earlier, you are vulnerable to CVE-2015-0884.