CVE-2022-50938
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.01%
- CWE
- CWE-428
- Published
- 2026-01-13
- Last modified
- 2026-03-13
Affected products
- Contpaqi CONTPAQ AdminPAQ
Weakness type
Related vulnerabilities
- CVE-2022-50935 — FLAME II MODEM USB - Unquoted Service Path
- CVE-2026-25866 — MobaXterm < 26.1 Notepad++ Unquoted Service Path
- CVE-2025-41359 — Multiple vulnerabilities in Small HTTP server by Smallsrv
- CVE-2023-54336 — Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
- CVE-2023-54331 — Outline 1.6.0 - Unquoted Service Path
- CVE-2022-50933 — Cain & Abel 4.9.56 - Unquoted Service Path
- CVE-2022-50930 — Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
- CVE-2022-50929 — Connectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path