There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
References
Link | Resource |
---|---|
https://www.ni.com/en-us/support/documentation/supplemental/21/unquoted-service-path-in-ni-service-locator.html | Patch Vendor Advisory |
https://www.ni.com/en-us/support/documentation/supplemental/21/unquoted-service-path-in-ni-service-locator.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.ni.com/en-us/support/documentation/supplemental/21/unquoted-service-path-in-ni-service-locator.html - Patch, Vendor Advisory |
Information
Published : 2021-11-12 21:15
Updated : 2024-11-21 06:27
NVD link : CVE-2021-42563
Mitre link : CVE-2021-42563
CVE.ORG link : CVE-2021-42563
JSON object : View
Products Affected
microsoft
- windows
ni
- ni_service_locator
CWE
CWE-428
Unquoted Search Path or Element