CVE-2021-47806
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject malicious executables and escalate privileges.
- Affected products
- Dupscout
- Flexense Dup Scout
- = 13.5.28
- Fix
- Available
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (12th percentile)
- Weakness
- CWE-428
- NVD status
- Analyzed
- Published
- 2026-01-15
CVE-2021-47806 at NVD
No indexed exploits for CVE-2021-47806 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-47806 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.