Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47889. PoCs published by Victor Mondragón.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in Softros LAN Messenger 9.6.4. The vulnerability allows local privilege escalation due to improper handling of spaces in the service path.
Description
Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Softros Systems\Softros Messenger\Spell Checker\' to inject malicious executables and escalate privileges.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in Softros LAN Messenger 9.6.4. The vulnerability allows local privilege escalation due to improper handling of spaces in the service path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H