Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47807. PoCs published by Brian Rodriguez.
AI-analyzed exploit summary This is a writeup detailing the discovery of an unquoted service path vulnerability in Sync Breeze 13.6.18. It includes steps to identify the vulnerability using WMIC and SC commands but does not contain executable exploit code.
Description
Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located in 'Program Files' directories to inject malicious executables and escalate privileges.
Exploits (1)
This is a writeup detailing the discovery of an unquoted service path vulnerability in Sync Breeze 13.6.18. It includes steps to identify the vulnerability using WMIC and SC commands but does not contain executable exploit code.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H