Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-27673 — ASUS Control Center Express =< 01.06.15 - Unquoted Service Path | Kitploit
Tools/GitHubGitHub/alaatk/cve-2024-27673
Privilege EscalationVulnerability AnalysisExploitationBinary Exploitation
GitHubalaatk/cve-2024-27673

CVE-2024-27673

ASUS Control Center Express =< 01.06.15 - Unquoted Service Path

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-27673

ASUS Control Center Express =< 01.06.15 - Unquoted Service Path

Description:

ASUS Control Center Express Version =< 01.06.15 contains an unquoted service path which allows attackers to escalate privileges to the system level. Assuming attackers have write access to C:, the attackers can abuse the Asus service "Apro console service"/apro_console.exe which upon restarting will invoke C:\Program.exe with SYSTEM privileges.

The binary path of the service alone isn't susceptible, but upon its initiation, it will execute C:\program.exe as SYSTEM.

Impacted service(s)

Service Name: AProConsoleService

binary impacted: apro_console.exe

program.exe

Alt text

Risk

In case of a poorly configured system, where a low privileged user could write to C:\ directory, they could use it to elevate their privileges to SYSTEM.

Discovered by:

Alaa Kachouh

Download Tool