Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Genexus
Genexus protection Server Microsoft Microsoft windows |
|
| Vendors & Products |
Genexus
Genexus protection Server Microsoft Microsoft windows |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations. | |
| Title | Genexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-11T21:33:58.572Z
Updated: 2025-12-11T21:33:58.572Z
Reserved: 2025-12-10T23:46:14.009Z
Link: CVE-2024-58288
No data.
Status : Received
Published: 2025-12-11T22:15:49.373
Modified: 2025-12-11T22:15:49.373
Link: CVE-2024-58288
No data.