CVE-2021-47806
HIGHDup Scout 13.5.28 - Unquoted Service Path Privilege Escalation via Windows Service Configuration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47806. PoCs published by Brian Rodriguez.
AI-analyzed exploit summary This is a writeup detailing the discovery of an unquoted service path vulnerability in Dup Scout Server and Enterprise versions 13.5.28. The vulnerability allows for potential local privilege escalation due to improper handling of service paths containing spaces.
Description
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject malicious executables and escalate privileges.
Exploits (1)
This is a writeup detailing the discovery of an unquoted service path vulnerability in Dup Scout Server and Enterprise versions 13.5.28. The vulnerability allows for potential local privilege escalation due to improper handling of service paths containing spaces.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H