216.73.216.233

CVE-2021-47974

· Published 16/05/2026 16:16 · Modified 16/05/2026 16:16

Labels: CVE-2021-47974 2026-05-16CVE-2021-47974CWE-428[email protected]

Essential information

Published
16/05/2026 16:16
Modified
16/05/2026 16:16
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary code with LocalSystem privileges when services restart.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vx search / vx search cpe:2.3:a:vx_search:vx_search:13.5.28:*:*:*:*:*:*:*
vx search / vx search server cpe:2.3:a:vx_search:vx_search_server:*:*:*:*:*:*:*:*
vx search / vx search enterprise cpe:2.3:a:vx_search:vx_search_enterprise:*:*:*:*:*:*:*:*

References