PT-2026-2414 · Contpaqi · Adminpaq

Angel Canseco

·

Publicado

2026-01-13

·

Atualizado

2026-01-14

·

CVE-2022-50938

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CONTPAQi AdminPAQ version 14.0.0
Description The software contains an unquoted service path issue in the AppKeyLicenseServer service, which operates with LocalSystem privileges. An attacker can exploit this to inject malicious code into the service binary path. This could lead to the execution of arbitrary code with elevated system privileges when the service starts.
Recommendations Ensure the service path is properly quoted to prevent malicious code injection.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-50938

Produtos afetados

Adminpaq