CVE-2021-47985

HIGH

Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47985. PoCs published by Brian Rodriguez.

AI-analyzed exploit summary This is a technical writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. It includes steps to identify the vulnerability using Windows commands and confirms the service configuration, but does not include functional exploit code.

Description

Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.

Exploits (1)

exploitdb WRITEUP
by Brian Rodriguez · textlocalwindows
https://www.exploit-db.com/exploits/50061

This is a technical writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. It includes steps to identify the vulnerability using Windows commands and confirms the service configuration, but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: SAPSprint 7.60
Auth required
Prerequisites: Local access to the system · Ability to execute commands as an administrator or privileged user
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-50061
https://www.exploit-db.com/exploits/50061
Product product
Official Product Homepage
https://brother.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
https://www.vulncheck.com/advisories/brother-sapsprint-unquoted-service-path-privilege-escalation

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Brother/SAPSprint 7.60
Published Jun 19, 2026
Tracked Since Jun 19, 2026