CVE-2021-47810: WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path
WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\SERVER\WkSvW32.exe' to inject malicious executables and escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47810?
CVE-2021-47810 is considered to be a high-severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
How do I fix CVE-2021-47810?
To fix CVE-2021-47810, you should ensure that the service path in WkSvW32.exe is properly quoted to prevent unquoted service path vulnerabilities.
What versions of software are affected by CVE-2021-47810?
CVE-2021-47810 affects WibuKey Runtime version 6.51 specifically.
Who can exploit CVE-2021-47810?
Local attackers with access to the affected system can exploit CVE-2021-47810.
What is the potential impact of CVE-2021-47810?
The potential impact of CVE-2021-47810 includes unauthorized execution of arbitrary code, leading to system compromise.