Description
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions during service startup.
References
Product
https://www.exploit-db.com/exploits/50431
ExploitThird Party Advisory
https://www.vulncheck.com/advisories/macro-expert-unquoted-service-path
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-16T00:16:21.130Z
1 month agoLast modified
2026-01-21T22:24:18.603Z
4 weeks ago