PT-2026-3043 · 10 Strike · Network Inventory Explorer Pro

Brian Rodriguez

·

Published

2026-01-15

·

Updated

2026-01-30

·

CVE-2021-47767

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions 10-Strike Network Inventory Explorer Pro version 9.31
Description The software contains an unquoted service path vulnerability in the srvInventoryWebServer service, which runs with LocalSystem privileges. An attacker can exploit this by placing malicious executables in potential path segments. Successful exploitation could lead to privilege escalation and code execution with system-level permissions.
Recommendations Ensure the service path for srvInventoryWebServer is properly quoted to prevent the execution of unauthorized executables.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2021-47767

Affected Products

Network Inventory Explorer Pro