CVE-2023-53947

HIGH

OCS Inventory NG <2.3.0.0 - Privilege Escalation

Title source: llm

Description

OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.

Exploits (1)

exploitdb WORKING POC
by msd0pe · textlocalwindows
https://www.exploit-db.com/exploits/51389

Scores

CVSS v3 8.4
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
oscinventory/OCS Inventory NG < 2.3.0.0
Published Dec 19, 2025
Tracked Since Feb 18, 2026