EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Easeus
Easeus data Recovery |
|
| Vendors & Products |
Easeus
Easeus data Recovery |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges. | |
| Title | EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:52.098Z
Updated: 2026-01-14T16:06:40.140Z
Reserved: 2026-01-11T13:14:18.876Z
Link: CVE-2022-50914
Updated: 2026-01-14T16:06:33.757Z
Status : Awaiting Analysis
Published: 2026-01-13T23:15:54.713
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50914
No data.