CVE-2022-50808

HIGH

CoolerMaster MasterPlus <1.8.5 - Code Injection

Title source: llm

Description

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.

Exploits (1)

exploitdb WRITEUP
by Damian Semon Jr · textlocalwindows
https://www.exploit-db.com/exploits/51159

Scores

CVSS v3 8.4
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
Cooler Master Technology Inc./Cooler Master MasterPlus 1.8.5
Published Jan 13, 2026
Tracked Since Feb 18, 2026