Description
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
msd0pe
References
www.exploit-db.com/exploits/51389 (ExploitDB-51389)
github.com/OCSInventory-NG/WindowsAgent (Official Product Homepage)
www.vulncheck.com/...uoted-service-path-privilege-escalation (VulnCheck Advisory: OCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege Escalation)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.