CVE-2021-42563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
12/11/2021
Last modified:
16/11/2021

Description

There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ni:ni_service_locator:*:*:*:*:*:*:*:* 18.0.0.49152 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*