Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
2015-02-28T02:59:33.767
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | toshiba | bluetooth_stack | 9.10.27\(t\) | Yes |
Operating System | microsoft | windows | * | No |
Application | toshiba | service_station | ≤ 2.2.13 | Yes |