Description


Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions during service startup.

Related CPE's


Weaknesses



CWE-428

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-16T00:16:21.130Z

1 month ago

Last modified

2026-01-21T22:24:18.603Z

4 weeks ago