Epson EasyMP Network Projection Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Epson EasyMP Network Projection version 2.81, specifically within the EMP_NSWLSV service, due to an unquoted service path. This flaw enables local users to potentially execute arbitrary code. The unquoted path can be exploited by injecting malicious code into the application's installation directory, which would then execute with LocalSystem privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code with elevated privileges.

Reproduction

The vulnerability can be reproduced by exploiting the unquoted service path of the EMP_NSWLSV service. After injecting malicious code into the system root path, undetected by the operating system or other security applications, the code could be executed during application startup or reboot, taking advantage of the elevated privileges of the service.

Added: Feb 1, 2026, 3:18 PM
Updated: Feb 1, 2026, 3:18 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
4.2
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.