There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
References
Link | Resource |
---|---|
https://www.ni.com/en-us/support/documentation/supplemental/21/unquoted-service-path-in-ni-service-locator.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
16 Nov 2021, 18:30
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-428 | |
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:ni:ni_service_locator:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.ni.com/en-us/support/documentation/supplemental/21/unquoted-service-path-in-ni-service-locator.html - Patch, Vendor Advisory |
12 Nov 2021, 22:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-12 21:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-42563
Mitre link : CVE-2021-42563
CVE.ORG link : CVE-2021-42563
JSON object : View
Products Affected
microsoft
- windows
ni
- ni_service_locator
CWE
CWE-428
Unquoted Search Path or Element