CVE-2021-47862

HIGH

Hi-Rez Studios 5.1.6.3 - Code Injection

Title source: llm

Description

Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

Exploits (1)

exploitdb WRITEUP
by Ekrem Can Kök · textlocalwindows
https://www.exploit-db.com/exploits/49701

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
HI-REZ STUDIOS/HiPatchService 5.1.6.3
Published Jan 21, 2026
Tracked Since Feb 18, 2026