Executive brief
Network Inventory Advisor, a tool used by IT teams to manage and audit hardware and software assets across a network, contains a configuration flaw in its background service. A local user with limited access to a computer running this software can exploit this flaw to gain full administrative control (LocalSystem privileges). This could allow an attacker to bypass security restrictions, access sensitive data, or disrupt operations on the affected machine.
Technical details
The 'niaservice' service in Network Inventory Advisor version 5.0.26.0 is installed with an unquoted service path containing spaces (e.g., 'C:\Program Files (x86)\ClearApps\Network Inventory Advisor\niaservice.exe'). This constitutes a CWE-428 vulnerability where the Windows Service Control Manager may attempt to execute files in intermediate directories if they match the path fragments. A local attacker with low privileges can place a malicious executable in a parent directory (such as 'C:\Program Files (x86)\ClearApps\Network.exe'). When the service starts or restarts, the system will execute the attacker's file with LocalSystem privileges. This vulnerability requires local file system access but no user interaction.
Affected products
- ClearApps Network Inventory Advisor 5.0.26.0
Timeline
- 2019-11-04: disclosed: Initial exploit discovery by Samuel DiazL
- 2026-06-19: advisory: NVD and VulnCheck published advisory details