CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
History

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Contpaqi
Contpaqi adminpaq
Vendors & Products Contpaqi
Contpaqi adminpaq

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
Title CONTPAQi® AdminPAQ 14.0.0 - Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-13T22:52:03.138Z

Updated: 2026-01-13T22:52:03.138Z

Reserved: 2026-01-11T13:34:26.330Z

Link: CVE-2022-50938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-13T23:15:59.057

Modified: 2026-01-13T23:15:59.057

Link: CVE-2022-50938

cve-icon Redhat

No data.