Sheed Antivirus Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Sheed AntiVirus version 2.3, specifically within the ShavProt service. The issue arises from an unquoted service path, which allows local attackers to exploit the service binary path. By inserting a malicious executable into the unquoted path and triggering a service restart or system reboot, attackers can execute code with LocalSystem privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling local attackers to execute code with elevated rights.

Reproduction

To reproduce this vulnerability, first verify the presence of Sheed AntiVirus version 2.3 installed on the system. Check the service configuration for ShavProt to confirm the unquoted service path. Once confirmed, insert a malicious executable into the path of the ShavProt service. After placing the executable, either restart the ShavProt service or reboot the system. The malicious code will be executed with LocalSystem privileges, demonstrating the successful exploitation of the vulnerability.

Added: Apr 4, 2026, 2:25 PM
Updated: Apr 4, 2026, 2:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
5.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.