Description
Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.
Problem types
CWE-428: Unquoted Search Path or Element
Product status
9.7.2.10
Credits
SamAlucard, Sam Alucard
References
www.exploit-db.com/exploits/52065 (ExploitDB-52065)
www.genexus.com/es/ (Official Genexus Homepage)
www.genexus.com/en/developers/downloadcenter?data=;; (Genexus Software Download Center)
www.vulncheck.com/...uoted-service-path-privilege-escalation (VulnCheck Advisory: Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.