PT-2025-52518 · Unknown · Ocs Inventory Ng

Msd0Pe

·

Published

2025-12-19

·

Updated

2025-12-20

·

CVE-2023-53947

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OCS Inventory NG version 2.3.0.0
Description The software contains an unquoted service path vulnerability. This allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger a service restart to execute code with elevated system privileges.
Recommendations Ensure the service path is properly quoted to prevent the execution of unauthorized code.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2023-53947

Affected Products

Ocs Inventory Ng