Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47845. PoCs published by Erick Galindo.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in Spy Emergency 25.0.650. The vulnerability allows for potential privilege escalation by exploiting the lack of quotes around the service executable path.
Description
Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system startup or service restart.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in Spy Emergency 25.0.650. The vulnerability allows for potential privilege escalation by exploiting the lack of quotes around the service executable path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H