Home

Description

PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Primera Technology\PTPublisher\UsbFlashDongleService.exe' to inject malicious executables and gain system-level access.

PUBLISHED Reserved 2026-01-11 | Published 2026-01-13 | Updated 2026-01-14 | Assigner VulnCheck




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

Unquoted Search Path or Element

Product status

2.3.4
affected

Credits

bios finder

References

www.exploit-db.com/exploits/50885 (ExploitDB-50885) exploit

www.primera.com/ (Primera Technology Official Homepage) product

www.vulncheck.com/...ories/ptpublisher-unquoted-service-path (VulnCheck Advisory: PTPublisher 2.3.4 - Unquoted Service Path) third-party-advisory

cve.org (CVE-2022-50915)

nvd.nist.gov (CVE-2022-50915)

Download JSON