CVE-2021-42563

HIGH

NI Service Locator <18.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
ni/ni_service_locator < 18.0.0.49152
Published Nov 12, 2021
Tracked Since Feb 18, 2026