Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System access.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System access. | |
| Title | Dynojet Power Core 2.3.0 - Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-15T18:26:39.411Z
Reserved: 2026-01-14T14:39:44.736Z
Link: CVE-2021-47773
Updated: 2026-01-15T16:12:30.804Z
Status : Received
Published: 2026-01-15T16:16:09.003
Modified: 2026-01-15T19:16:02.470
Link: CVE-2021-47773
No data.
OpenCVE Enrichment
No data.