CVE-2021-47845
Spy Emergency 25.0.650 - Unquoted Service Path
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
16 ene 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system startup or service restart.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Spy-Emergency · Spy Emergency¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →