Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://public.support.unisys.com/common/public/vulnerability/NVD_Home.aspx | vendor advisory |
https://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=64 | patch vendor advisory |