Executive brief
Vembu StoreGrid is a backup solution used by businesses to protect and manage data. A security flaw in how the software is installed on Windows allows a user with low-level access to the computer to gain full administrative control. By placing a malicious file in a specific location, an attacker can trick the system into running their code with the highest possible privileges, potentially leading to a complete takeover of the backup server.
Technical details
Vembu StoreGrid 4.0 is vulnerable to an unquoted service path (CWE-428) within the 'RemoteBackup' and 'RemoteBackup_webServer' Windows services. The binary paths for these services (e.g., C:\Program Files\MSP\RemoteBackup\bin\StoreGrid.exe) are not enclosed in quotation marks, leading Windows to attempt to execute files at intercepting points in the path if spaces are present. A local attacker with file system permissions to write to the root or intermediate directories can place a malicious executable (such as C:\Program.exe) that will be executed with LocalSystem privileges when the service restarts or the system reboots. This allows for full local privilege escalation from a standard user to System.
Affected products
- Vembu StoreGrid 4.0
Timeline
- 2016-10-19: disclosed: Initial exploit published on Exploit-DB
- 2026-06-19: advisory: NVD/VulnCheck advisory published