Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47874. PoCs published by Mohammed Alshehri.
AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in VFS for Git 1.0.21014.1, where the service path 'C:\Program Files\GVFS\GVFS.Service.exe' could allow local privilege escalation if an attacker plants a malicious executable in a path with spaces. However, no actual exploit code is provided.
Description
VFS for Git 1.0.21014.1 contains an unquoted service path vulnerability in the GVFS.Service Windows service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem privileges during service startup or system reboot.
Exploits (1)
This exploit describes an unquoted service path vulnerability in VFS for Git 1.0.21014.1, where the service path 'C:\Program Files\GVFS\GVFS.Service.exe' could allow local privilege escalation if an attacker plants a malicious executable in a path with spaces. However, no actual exploit code is provided.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H