Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50938. PoCs published by Angel Canseco.
AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in CONTPAQi® AdminPAQ 14.0.0. The vulnerability allows local privilege escalation by exploiting the service path to execute arbitrary code with elevated privileges upon system reboot.
Description
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
Exploits (1)
This is a writeup describing an unquoted service path vulnerability in CONTPAQi® AdminPAQ 14.0.0. The vulnerability allows local privilege escalation by exploiting the service path to execute arbitrary code with elevated privileges upon system reboot.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H