Spy Emergency Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Spy Emergency build 23.0.205, specifically within the SpyEmrgHealth and SpyEmrgSrv services. This vulnerability arises from an unquoted service path, allowing local attackers to escalate privileges by placing malicious executables in the service path. The injected executables can be executed with LocalSystem privileges when the service is restarted or the system is rebooted.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, with executed code running under the LocalSystem account, which has extensive rights on the system.

Reproduction

To reproduce this vulnerability, a local attacker must place an executable file in the unquoted service path of the vulnerable Spy Emergency services. Once the executable is in place, the attacker can trigger the execution by restarting the service or rebooting the system.

Added: Apr 4, 2026, 2:27 PM
Updated: Apr 4, 2026, 2:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
5.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.