TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/50314 | Exploit Third Party Advisory VDB Entry |
| https://www.totalav.com | Product |
| https://www.vulncheck.com/advisories/totalav-unquoted-service-path | Third Party Advisory |
| https://www.exploit-db.com/exploits/50314 | Exploit Third Party Advisory VDB Entry |
Configurations
History
09 Feb 2026, 14:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Totalav totalav
Totalav |
|
| CPE | cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:* | |
| References | () https://www.exploit-db.com/exploits/50314 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.totalav.com - Product | |
| References | () https://www.vulncheck.com/advisories/totalav-unquoted-service-path - Third Party Advisory |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/50314 - |
16 Jan 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 00:16
Updated : 2026-02-09 14:08
NVD link : CVE-2021-47787
Mitre link : CVE-2021-47787
CVE.ORG link : CVE-2021-47787
JSON object : View
Products Affected
totalav
- totalav
CWE
CWE-428
Unquoted Search Path or Element
