Dynojet Power Core Unquoted Service Path Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in Dynojet Power Core version 2.3.0, specifically within the DJ.UpdateService, due to an unquoted service path. This flaw allows local authenticated users to potentially execute code with elevated privileges. Exploitation involves placing malicious executables in the service's file path, which can then be executed with Local System rights.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution with elevated privileges, allowing a local user to gain Local System access.

Reproduction

The vulnerability can be reproduced by placing a malicious executable in the system root path. Once the executable is in place, the DJ.UpdateService can be started manually by any authenticated user. If the service is executed, the malicious code will run with Local System privileges.

Added: Jan 15, 2026, 4:34 PM
Updated: Jan 15, 2026, 7:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.