Unquoted Service Path Vulnerability on Windows

Unquoted Service Path Vulnerability on Windows

This vulnerability has been addressed by SBT.  Please refer to the following information below to make necessary Ranger updates to prevent this vulnerability on workstations:
  1. SBTLogServiceWindows is already a deprecated service. No Ranger Core installer newer than 4.5.x.x should install this service.This Service path will linger even after uninstalling the old plugins, but you can safely delete this service path (without affecting SBTLogService)
  2. All other Services Ranger installs have also been certified for quoted paths starting from Ranger Core 4.8.1.6-X.X.X.X. Ranger Core before 4.8.1.6 might install SBT Log Service with an unquoted path.
  3. Ranger Remote Service installers starting from 2.2.1.7 will also not install any services with an unquoted path



Ranger® - The universal check scanner interface
Copyright © 2023 Silver Bullet Technology
www.sbullet.com

    • Related Articles

    • How can you start/stop Ranger Remote as a Windows Service?

      Ranger Remote as a Windows Service (Ranger Remote v2.0.0.0+) starts on installation. It also starts automatically on PC start up. To manually start/stop the server: You start/stop the service with the Command Prompt with Admin Rights: ' net start ...
    • Windows 7 - Scanner Compatibility List

      Windows 7 support NOTE: Ranger code supports this OS. Manufacturer support is noted below. Make Model 32-bit 64-bit Notes BancTec EasyScan No No Scanner is discontinued. No planned support. Canon CR-190i Yes Yes OS support released in Ranger ...
    • Windows 10 - Scanner Compatibility List

      Windows 10 support NOTE: Ranger code supports this OS. Manufacturer support is noted below. Make Model 32-bit 64-bit Notes Canon CR-L1 Yes Yes Certified in version 4.7.0.2-2.0.0.4 Canon CR-50/CR-80 Yes Yes Certified in version 4.4.0.1-1.2.1.0 Canon ...
    • Windows 8 - Scanner Compatibility List

      Windows 8 support NOTE: Ranger code supports this OS. Manufacturer support is noted below. Make Model 32-bit 64-bit Notes Canon CR-190i Yes Yes Certified in version 4.2.0-1.5.0.8 Canon CR-180II No No No plans to support W8. Last supported OS was W7. ...
    • How to point Ranger at a Ranger Remote service running on a different PC

      By default, an insecure loopback URL is used for the socket connection between Ranger and Ranger Remote, listening on port 9002. The IP Address for local loopback is ?127.0.0.1?. In order to override the target IP address of the Ranger Remote ...