CVE-2021-47896
HIGHPDF Complete Corporate Edition 4.1.45 - Code Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47896. PoCs published by Ismael Nava.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in PDFCOMPLETE Corporate Edition 4.1.45. The vulnerability allows local privilege escalation due to the service path containing spaces and not being enclosed in quotes.
Description
PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated LocalSystem privileges.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in PDFCOMPLETE Corporate Edition 4.1.45. The vulnerability allows local privilege escalation due to the service path containing spaces and not being enclosed in quotes.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H