PT-2026-3043 · 10 Strike · Network Inventory Explorer Pro

Brian Rodriguez

·

Publicado

2026-01-15

·

Atualizado

2026-01-30

·

CVE-2021-47767

CVSS v4.0

8.5

Alta

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions 10-Strike Network Inventory Explorer Pro version 9.31
Description The software contains an unquoted service path vulnerability in the srvInventoryWebServer service, which runs with LocalSystem privileges. An attacker can exploit this by placing malicious executables in potential path segments. Successful exploitation could lead to privilege escalation and code execution with system-level permissions.
Recommendations Ensure the service path for srvInventoryWebServer is properly quoted to prevent the execution of unauthorized executables.

Exploit

Correção

LPE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-47767

Produtos afetados

Network Inventory Explorer Pro