CVE-2021-47787

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
References
Link Resource
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
https://www.totalav.com Product
https://www.vulncheck.com/advisories/totalav-unquoted-service-path Third Party Advisory
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:*

History

17 Jun 2026, 04:18

Type Values Removed Values Added
Summary
  • (es) TotalAV 5.15.69 contiene una vulnerabilidad de ruta de servicio sin comillas en múltiples servicios del sistema que se ejecutan con privilegios de LocalSystem. Los atacantes pueden colocar ejecutables maliciosos en segmentos de ruta sin comillas específicos para obtener potencialmente acceso a nivel de SYSTEM explotando la configuración de la ruta del servicio.

09 Feb 2026, 14:08

Type Values Removed Values Added
CPE cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:*
First Time Totalav totalav
Totalav
References () https://www.exploit-db.com/exploits/50314 - () https://www.exploit-db.com/exploits/50314 - Exploit, Third Party Advisory, VDB Entry
References () https://www.totalav.com - () https://www.totalav.com - Product
References () https://www.vulncheck.com/advisories/totalav-unquoted-service-path - () https://www.vulncheck.com/advisories/totalav-unquoted-service-path - Third Party Advisory

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50314 - () https://www.exploit-db.com/exploits/50314 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47787

Mitre link : CVE-2021-47787

CVE.ORG link : CVE-2021-47787


JSON object : View

Products Affected

totalav

  • totalav
CWE
CWE-428

Unquoted Search Path or Element