PT-2025-50742 · Genexus+1 · Genexus Protection Server+1

Published

2025-12-11

·

Updated

2025-12-12

·

CVE-2024-58288

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Genexus Protection Server version 9.7.2.10
Description The Genexus Protection Server software contains a flaw due to an unquoted service path in the configuration of the protsrvservice Windows service. This allows attackers to potentially execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.
Recommendations Ensure the service path for the protsrvservice Windows service is properly quoted to prevent exploitation.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2024-58288

Affected Products

Genexus Protection Server
Windows