Unquoted Service Path Vulnerability in Disk Savvy by Flexense
CVE-2021-47805
Key Information:
- Vendor
Disksavvy
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
What is CVE-2021-47805?
Disk Savvy version 13.6.14 contains a vulnerability in its Windows service configuration due to the use of an unquoted service path. This flaw can allow local attackers to exploit the service path, leading to the execution of arbitrary code with elevated LocalSystem privileges. By injecting malicious executables into the service binary path, unauthorized access and control over the affected system can be achieved. It is crucial for users to secure their installations against such vulnerabilities.
Affected Version(s)
Disk Savvy 13.6.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
