Skip to content

Unquoted Service Paths (Win)

Windows services often specify executable paths in their configuration. When these paths are unquoted (i.e., not enclosed in double quotes), the operating system may misinterpret the path as multiple separate components, enabling path traversal and privilege escalation. This is a common vulnerability in misconfigured services, particularly when the service executable is located in a directory with symbolic links or when the path includes spaces.


How Unquoted Service Paths Work

A service path like C:\Program Files\MyService\service.exe (without quotes) is parsed by the system as a sequence of directories and files. If an attacker places a malicious executable (e.g., service.exe) in a directory that appears earlier in the path, the service may inadvertently execute the malicious file instead of the intended one. For example:

C:\Program Files\MyService\service.exe

If the system resolves C:\Program Files\ first and finds a service.exe there, it will execute that file instead of the one in MyService\.

This behavior is exploited when the service runs with elevated privileges (e.g., as LocalSystem), allowing the attacker to escalate privileges by replacing the legitimate executable with a malicious one.


Identifying Unquoted Service Paths

Use the sc command to query service configurations:

sc qc <service_name>

Look for the BINARYPATH field. If it contains spaces and is not enclosed in quotes, it’s a candidate for exploitation. For example:

[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: wuauserv
DISPLAY_NAME: Windows Update
BINARYPATH: C:\Windows\System32\svchost.exe -k netsvcs -p -s wuauserv

In this case, the path is quoted and not vulnerable. A vulnerable example might look like:

BINARYPATH: C:\Program Files\MyService\service.exe

Exploitation Example

  1. Identify the service: Use sc query to list all services.
  2. Locate the unquoted path: Use sc qc to check for unquoted paths.
  3. Replace the executable: Place a malicious file (e.g., service.exe) in a directory that appears in the path. For example:

    C:\Program Files\MyService\service.exe
    
    If the service path is C:\Program Files\MyService\service.exe, and the attacker creates a service.exe in C:\Program Files\, the service will execute the malicious file.

  4. Restart the service: Use sc stop <service_name> followed by sc start <service_name> to trigger execution of the malicious payload.


Mitigation

  • Quote service paths: Always enclose paths in quotes to prevent misinterpretation.
  • Use absolute paths: Avoid relative paths that could be resolved ambiguously.
  • Restrict permissions: Ensure services run with the minimum necessary privileges.

Key takeaways

  • Unquoted service paths allow path traversal by splitting the path into components.
  • Attackers can replace legitimate executables with malicious ones to escalate privileges.
  • Use sc qc to identify vulnerable services and sc stop/start to trigger payloads.
  • Always quote service paths and restrict service permissions to mitigate risks.