PT-2025-52702 · Unknown · Sound4 Server Service

Published

2025-12-22

·

Updated

2025-12-23

·

CVE-2023-53965

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 Server Service version 4.1.102
Description SOUND4 Server Service version 4.1.102 contains an unquoted service path issue that may allow local users with limited privileges to execute code with higher system privileges. An attacker can exploit the unquoted binary path by placing malicious code in the system root path, which could then execute with LocalSystem privileges when the service starts.
Recommendations Versions prior to 4.1.102 are not affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Weakness Enumeration

Related Identifiers

CVE-2023-53965

Affected Products

Sound4 Server Service