RULE(RULE ID:338237)

Rule General Information
Release Date: 2024-07-09
Rule Name: MSService init.do SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: MSService is a versatile Microsoft service support tool designed to offer system management, maintenance, and troubleshooting capabilities to ensure the stability and performance of the operating system. The init.do interface of MSService has a SQL injection vulnerability, which attackers can exploit to execute malicious SQL commands, potentially gaining unauthorized access to, modifying, or deleting sensitive information in the database, thereby posing a severe threat to data security and system integrity.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.