CVE-2021-47773 is an unquoted service path vulnerability in Dynojet Power Core 2.3.0's DJ.UpdateService. This flaw allows local authenticated users to achieve elevated privileges by placing malicious executables in the service's file path, potentially leading to Local System access. Rated with a CVSS score of 7.8 (HIGH), it requires local access and low privileges but can result in high impact to confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.0CPE matchmatch criteria | cpe:2.3:a:dynojet:power_core:2.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.