PT-2026-2414 · Contpaqi · Adminpaq

Angel Canseco

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2022-50938

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CONTPAQi AdminPAQ version 14.0.0
Description The software contains an unquoted service path issue in the AppKeyLicenseServer service, which operates with LocalSystem privileges. An attacker can exploit this to inject malicious code into the service binary path. This could lead to the execution of arbitrary code with elevated system privileges when the service starts.
Recommendations Ensure the service path is properly quoted to prevent malicious code injection.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-50938

Affected Products

Adminpaq