Nssm-2.24 Privilege Escalation -
: Misconfigured permissions on nssm.exe allowed local privilege escalation. Mitigation and Defense
Understanding NSSM-2.24 and Potential Privilege Escalation NSSM (the ) version 2.24 is a widely used utility that allows administrators to wrap any executable or script into a Windows service. While NSSM itself is not inherently "vulnerable" in its core code, the way it is deployed and configured—especially in version 2.24—frequently introduces Local Privilege Escalation (LPE) vulnerabilities in the host systems it manages. Common Attack Vectors Involving NSSM-2.24 nssm-2.24 privilege escalation
When NSSM 2.24 is used to install a service, it might not properly quote the paths to the executable if those paths contain spaces. : Misconfigured permissions on nssm