Unquoted Service Path Vulnerability in eBeam Education Suite by eBeam
CVE-2021-47878
Key Information:
- Vendor
Luidia
- Status
- Vendor
- CVE Published:
- 21 January 2026
Badges
What is CVE-2021-47878?
eBeam Education Suite version 2.5.0.9 is impacted by an unquoted service path vulnerability within the eBeam Device Service. This flaw enables local users to execute arbitrary code with elevated privileges. By exploiting the incorrect quoting in the service configuration, attackers may inject malicious commands that execute with LocalSystem privileges during the startup of the service. This could lead to significant security risks and requires immediate attention to mitigate potential exploitation.
Affected Version(s)
eBeam Education Suite 2.5.0.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
