CVE-2026-33253 Details
Description
SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
A vulnerability exists in SANUPS SOFTWARE provided by SANYO DENKI CO., LTD., where Windows services are registered with unquoted file paths. This issue affects SANUPS SOFTWARE STANDALONE versions 1.0.1 to 1.1.4, as well as SANUPS SOFTWARE versions 2.0.0 to 2.0.2 and 1.0.0 to 1.1.4. A user with write permission on the root directory of the system drive could exploit this vulnerability to execute arbitrary code with SYSTEM privileges. The vulnerability arises because the installation path can be manipulated to execute malicious payloads as a service.
Users are advised to update SANUPS SOFTWARE STANDALONE to version 1.1.5 or SANUPS SOFTWARE to version 2.0.3. For SANUPS SOFTWARE versions 1.0.0 to 1.1.4, upgrade to version 3.0.1. Instructions for downloading the updated versions are available on the SANYO DENKI website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | New CVE Received | [email protected] |