CVE-2023-53947
Severity CVSS v4.0:
HIGH
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
19/12/2025
Last modified:
19/12/2025
Description
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH



