CVE-2021-47787

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
References
Link Resource
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
https://www.totalav.com Product
https://www.vulncheck.com/advisories/totalav-unquoted-service-path Third Party Advisory
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-16 00:16

Updated : 2026-02-09 14:08


NVD link : CVE-2021-47787

Mitre link : CVE-2021-47787

CVE.ORG link : CVE-2021-47787


JSON object : View

Products Affected

totalav

  • totalav
CWE
CWE-428

Unquoted Search Path or Element