CVE-2021-47803 Details
Description
iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.
A vulnerability exists in iFunbox version 4.2 within the Apple Mobile Device Service, related to an unquoted service path. This flaw enables local attackers to execute code with elevated privileges. By inserting a malicious executable into the unquoted service path, attackers can execute it with LocalSystem rights when the service is restarted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 16, 2026CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/50040 | [email protected] | Exploit |
| https://www.i-funbox.com/en/index.html | [email protected] | ProductVendor |
| https://www.vulncheck.com/advisories/ifunbox-apple-mobile-device-service-unquoted-service-path | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| iFunbox | All versions |
CPE
Remediation
| |
| Apple Mobile Device Service | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | New CVE Received | [email protected] |
Volerion