CVE-2022-50808

HIGH

CoolerMaster MasterPlus <1.8.5 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-50808. PoCs published by Damian Semon Jr.

AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in CoolerMaster MasterPlus 1.8.5, where the service path lacks quotes, allowing potential privilege escalation via executable placement in a parent directory. The writeup includes steps to identify the vulnerability and exploit it by placing a malicious executable in the root of C:\.

Description

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.

Exploits (1)

exploitdb WRITEUP
by Damian Semon Jr · textlocalwindows
https://www.exploit-db.com/exploits/51159

This exploit describes an unquoted service path vulnerability in CoolerMaster MasterPlus 1.8.5, where the service path lacks quotes, allowing potential privilege escalation via executable placement in a parent directory. The writeup includes steps to identify the vulnerability and exploit it by placing a malicious executable in the root of C:\.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: CoolerMaster MasterPlus 1.8.5
Auth required
Prerequisites: Local access to the system · Ability to write to the root of C:\ · Service restart or system reboot
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources product
https://masterplus.coolermaster.com/
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51159

Scores

CVSS v3 8.4
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
Cooler Master Technology Inc./Cooler Master MasterPlus 1.8.5
Published Jan 13, 2026
Tracked Since Feb 18, 2026