PT-2026-2414 · Contpaqi · Adminpaq
Angel Canseco
·
Publicado
2026-01-13
·
Atualizado
2026-01-14
·
CVE-2022-50938
CVSS v3.1
8.4
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CONTPAQi AdminPAQ version 14.0.0
Description
The software contains an unquoted service path issue in the AppKeyLicenseServer service, which operates with LocalSystem privileges. An attacker can exploit this to inject malicious code into the service binary path. This could lead to the execution of arbitrary code with elevated system privileges when the service starts.
Recommendations
Ensure the service path is properly quoted to prevent malicious code injection.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adminpaq