Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47890. PoCs published by Victor Mondragón.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in LogonExpert 8.1. The vulnerability allows local privilege escalation due to the service path containing spaces and lacking quotes, enabling an attacker to place a malicious executable in the path.
Description
LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentially gaining elevated system access during service startup.
Exploits (1)
This is a technical writeup detailing an unquoted service path vulnerability in LogonExpert 8.1. The vulnerability allows local privilege escalation due to the service path containing spaces and lacking quotes, enabling an attacker to place a malicious executable in the path.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H