CVE-2021-47985
HIGHBrother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47985. PoCs published by Brian Rodriguez.
AI-analyzed exploit summary This is a technical writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. It includes steps to identify the vulnerability using Windows commands and confirms the service configuration, but does not include functional exploit code.
Description
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.
Exploits (1)
This is a technical writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. It includes steps to identify the vulnerability using Windows commands and confirms the service configuration, but does not include functional exploit code.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H