Can you test your products against a vulnerability product such as Nessus as many organisation will use such a product for vulnerability scanning or compliance reporting etc... and I have come across an issue as an example of where we see a vulnerability with your product.
Microsoft Windows Unquoted Service Path Enumeration
Description
The remote Windows host has at least one service installed that uses an unquoted service path, which contains at least one whitespace. A local attacker could gain elevated privileges by inserting an executable file in the path of the affected service.
Note that this is a generic test that will flag any application affected by the described vulnerability.
Solution
Ensure that any services that contain a space in the path enclose the path in quotes.
See Also
http://isc.sans.edu/diary.html?storyid=14464
http://cwe.mitre.org/data/definitions/428.html
http://www.commonexploits.com/?p=658
http://www.nessus.org/u?4aa6acbc
Output
Nessus found the following services with an untrusted path :
SWJMXBridgeSvc : C:\Program Files (x86)\Solarwinds\Orion\APM\jmxbridge\jsl\jsl.exe
SWLANsurveyor : C:\Program Files (x86)\SolarWinds\SolarWinds LANsurveyor\\SrvAnyTool\\SRVANY.EXE
| Port | | Hosts |
|---|
| 445 | 445 / tcp / cifs | |