CVE-2021-47896 Details
Description
PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated LocalSystem privileges.
A vulnerability exists in PDF Complete Corporate Edition version 4.1.45 due to an unquoted service path in the pdfcDispatcher service. This flaw allows local attackers to execute arbitrary code by injecting malicious executables into the service's binary location. The injected code would be executed with elevated LocalSystem privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 23, 2026CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/49558 | CISA-ADP | Exploit |
| https://pdf-complete.informer.com/download/ | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/49558 | [email protected] | Exploit |
| https://www.pdfcomplete.com/cms/dpl/tabid/111/Default.aspx?r=du2vH8r | [email protected] | Permission RequiredVendor |
| https://www.vulncheck.com/advisories/pdfcomplete-corporate-edition-pdfcdispatcher-unquoted-service-path | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PDF Complete Corporate Edition | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | New CVE Received | [email protected] |
Volerion