CVE-2019-25293: Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path
BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the unquoted service path vulnerability by ensuring the BstHdLogRotatorSvc service ImagePath is quoted (e.g., set the service binary path with quotes) for BlueStacks App Player 2.4.44.62.57.
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25293?
CVE-2019-25293 has a medium severity rating due to the potential for local attackers to execute arbitrary code.
How do I fix CVE-2019-25293?
To fix CVE-2019-25293, ensure that the service path for BstHdLogRotatorSvc is enclosed in quotes.
Who is affected by CVE-2019-25293?
Users of BlueStacks App Player version 2.4.44.62.57 are affected by CVE-2019-25293.
What kind of vulnerability is CVE-2019-25293?
CVE-2019-25293 is an unquoted service path vulnerability that allows for potential exploitation by local attackers.
Can CVE-2019-25293 be exploited remotely?
CVE-2019-25293 cannot be exploited remotely; it requires local access to the system.