CVE-2022-50915
HIGHPTPublisher 2.3.4 - Unquoted Service Path in PTProtect Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-50915. PoCs published by bios.
AI-analyzed exploit summary This is a writeup detailing the discovery of an unquoted service path vulnerability in PTPublisher v2.3.4. The vulnerability allows for potential local privilege escalation due to the service path not being enclosed in quotes.
Description
PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Primera Technology\PTPublisher\UsbFlashDongleService.exe' to inject malicious executables and gain system-level access.
Exploits (1)
This is a writeup detailing the discovery of an unquoted service path vulnerability in PTPublisher v2.3.4. The vulnerability allows for potential local privilege escalation due to the service path not being enclosed in quotes.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H