PT-2026-2414 · Contpaqi · Adminpaq
Angel Canseco
·
Published
2026-01-13
·
Updated
2026-01-14
·
CVE-2022-50938
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CONTPAQi AdminPAQ version 14.0.0
Description
The software contains an unquoted service path issue in the AppKeyLicenseServer service, which operates with LocalSystem privileges. An attacker can exploit this to inject malicious code into the service binary path. This could lead to the execution of arbitrary code with elevated system privileges when the service starts.
Recommendations
Ensure the service path is properly quoted to prevent malicious code injection.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adminpaq