Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47868

Опубликовано: 21 янв. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files \WINPAKPRO\WPCommandFileService Service.exe to inject malicious code that would execute with LocalSystem permissions.

EPSS

Процентиль: 2%
0.00012
Низкий

7.8 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 7.8
github
17 дней назад

WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files <x86>\WINPAKPRO\WPCommandFileService Service.exe to inject malicious code that would execute with LocalSystem permissions.

EPSS

Процентиль: 2%
0.00012
Низкий

7.8 High

CVSS3

Дефекты

CWE-428