Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34xc-rrm5-3hhj

Опубликовано: 23 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

EPSS

Процентиль: 5%
0.00022
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 месяцев назад

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

EPSS

Процентиль: 5%
0.00022
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-428