EIP-2026-117958
PRE-CVESpybot Search & Destroy 1.6.2 Security Center Service - Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117958. PoCs published by LiquidWorm.
AI-analyzed exploit summary This advisory describes an unquoted search path vulnerability in Spybot Search & Destroy 1.6.2's 'SBSDWSCService' service, allowing local privilege escalation via arbitrary code execution. The issue stems from the service's binary path lacking quotes, enabling path hijacking if an attacker places a malicious executable in the system root path.
Description
Spybot Search & Destroy 1.6.2 Security Center Service - Local Privilege Escalation
Exploits (1)
This advisory describes an unquoted search path vulnerability in Spybot Search & Destroy 1.6.2's 'SBSDWSCService' service, allowing local privilege escalation via arbitrary code execution. The issue stems from the service's binary path lacking quotes, enabling path hijacking if an attacker places a malicious executable in the system root path.