CVE-2021-47787

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
References
Link Resource
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
https://www.totalav.com Product
https://www.vulncheck.com/advisories/totalav-unquoted-service-path Third Party Advisory
https://www.exploit-db.com/exploits/50314 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:*

History

09 Feb 2026, 14:08

Type Values Removed Values Added
First Time Totalav totalav
Totalav
CPE cpe:2.3:a:totalav:totalav:5.15.69:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/50314 - () https://www.exploit-db.com/exploits/50314 - Exploit, Third Party Advisory, VDB Entry
References () https://www.totalav.com - () https://www.totalav.com - Product
References () https://www.vulncheck.com/advisories/totalav-unquoted-service-path - () https://www.vulncheck.com/advisories/totalav-unquoted-service-path - Third Party Advisory

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50314 - () https://www.exploit-db.com/exploits/50314 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-02-09 14:08


NVD link : CVE-2021-47787

Mitre link : CVE-2021-47787

CVE.ORG link : CVE-2021-47787


JSON object : View

Products Affected

totalav

  • totalav
CWE
CWE-428

Unquoted Search Path or Element