Vulnerability Description
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code with system-level permissions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 10-Strike | Network Inventory Explorer | 9.31 |
Related Weaknesses (CWE)
References
- https://www.10-strike.com/Product
- https://www.exploit-db.com/exploits/50494Exploit
- https://www.exploit-db.com/exploits/50494Exploit
FAQ
What is CVE-2021-47767?
CVE-2021-47767 is a vulnerability with a CVSS score of 7.8 (HIGH). 10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquot...
How severe is CVE-2021-47767?
CVE-2021-47767 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47767?
Check the references section above for vendor advisories and patch information. Affected products include: 10-Strike Network Inventory Explorer.