CVE-2021-47806

D

up Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject malicious executables and escalate privileges.

Configurations

Configuration 1 (hide)

cpe:2.3:a:flexense:dup_scout:13.5.28:*:*:*:*:*:*:*

History

30 Jan 2026, 00:54

Type Values Removed Values Added
First Time Flexense
Flexense dup Scout
CPE cpe:2.3:a:flexense:dup_scout:13.5.28:*:*:*:*:*:*:*
References () https://www.dupscout.com - () https://www.dupscout.com - Product
References () https://www.exploit-db.com/exploits/50025 - () https://www.exploit-db.com/exploits/50025 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/dup-scout-multiple-unquoted-service-path - () https://www.vulncheck.com/advisories/dup-scout-multiple-unquoted-service-path - Third Party Advisory

16 Jan 2026, 22:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50025 - () https://www.exploit-db.com/exploits/50025 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-01-30 00:54


NVD link : CVE-2021-47806

Mitre link : CVE-2021-47806

CVE.ORG link : CVE-2021-47806


JSON object : View

Products Affected
CWE
CWE-428

Unquoted Search Path or Element