iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.
History

Fri, 16 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared I-funbox
I-funbox ifunbox
Vendors & Products I-funbox
I-funbox ifunbox

Thu, 15 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.
Title iFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-15T23:25:47.367Z

Updated: 2026-01-16T15:53:23.307Z

Reserved: 2026-01-14T14:39:44.740Z

Link: CVE-2021-47803

cve-icon Vulnrichment

Updated: 2026-01-16T15:53:20.144Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T00:16:24.707

Modified: 2026-01-16T15:55:12.257

Link: CVE-2021-47803

cve-icon Redhat

No data.