CVE-2021-47974
VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary code with LocalSystem privileges when services restart.
- Affected products
- Vx Search
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.1% (2th percentile)
- Weakness
- CWE-428
- NVD status
- Deferred
- Published
- 2026-05-16
CVE-2021-47974 at NVD
No indexed exploits for CVE-2021-47974 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-47974 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.