Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50914. PoCs published by bios.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in EaseUS Data Recovery's 'ensserver.exe'. The vulnerability allows for potential privilege escalation if an attacker can place a malicious executable in the path.
Description
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in EaseUS Data Recovery's 'ensserver.exe'. The vulnerability allows for potential privilege escalation if an attacker can place a malicious executable in the path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H