TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
History

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Totalav
Totalav totalav
Vendors & Products Totalav
Totalav totalav

Thu, 15 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
Title TotalAV 5.15.69 - Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-16T21:12:31.193Z

Reserved: 2026-01-14T14:39:44.738Z

Link: CVE-2021-47787

cve-icon Vulnrichment

Updated: 2026-01-16T15:53:41.546Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-01-16T00:16:22.073

Modified: 2026-01-16T22:16:14.257

Link: CVE-2021-47787

cve-icon Redhat

No data.