PT-2026-4506 · Unknown · Logonexpert
Victor Mondragón
·
Published
2026-01-23
·
Updated
2026-01-24
·
CVE-2021-47890
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LogonExpert version 8.1
Description
LogonExpert 8.1 has an unquoted service path issue within the LogonExpertSvc service, which operates with LocalSystem privileges. This allows attackers to potentially place malicious executables in intermediate directories. Successful exploitation could lead to elevated system access when the service starts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logonexpert