PT-2026-3043 · 10 Strike · Network Inventory Explorer Pro

·

CVE-2021-47767

·

Published

2026-01-15

·

Updated

2026-01-30

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions 10-Strike Network Inventory Explorer Pro version 9.31
Description The software contains an unquoted service path vulnerability in the srvInventoryWebServer service, which runs with LocalSystem privileges. An attacker can exploit this by placing malicious executables in potential path segments. Successful exploitation could lead to privilege escalation and code execution with system-level permissions.
Recommendations Ensure the service path for srvInventoryWebServer is properly quoted to prevent the execution of unauthorized executables.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47767

Affected Products

Network Inventory Explorer Pro