CVE-2021-47823 Details
Description
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.
A vulnerability exists in Acer ePowerSvc version 6.0.3008.0, where an unquoted service path allows local users to execute code with elevated system privileges. The flaw arises because the service path can be exploited to inject malicious code that executes with LocalSystem permissions during the service's startup process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 16, 2026CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.acer.com | [email protected] | Vendor |
| https://www.exploit-db.com/exploits/49900 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/epowersvc-epowersvcexe-unquoted-service-path | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Acer ePowerSvc | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | New CVE Received | [email protected] |
Volerion