CVE-2021-47826: Acer Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with elevated LocalSystem privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47826?
CVE-2021-47826 has a medium severity rating due to the potential for local users to execute arbitrary code.
How do I fix CVE-2021-47826?
To mitigate CVE-2021-47826, correct the unquoted service path by enclosing the path in double quotes.
Who is affected by CVE-2021-47826?
CVE-2021-47826 affects users of Acer Backup Manager version 3.0.0.99.
What could an attacker gain by exploiting CVE-2021-47826?
An attacker exploiting CVE-2021-47826 could potentially gain elevated privileges on the affected system.
Is CVE-2021-47826 remotely exploitable?
CVE-2021-47826 is not remotely exploitable; it requires local access to the system.