OSAS Traverse Unquoted Service Path Vulnerability in TravExtensionHostSvc

Vulnerability

A vulnerability exists in OSAS Traverse Extension 11 within the TravExtensionHostSvc service, which operates with LocalSystem privileges. This unquoted service path vulnerability allows attackers to inject and execute malicious code by placing executable files in the service's path, potentially leading to elevated system access.

Impact

Exploitation of this vulnerability could allow for unauthorized code execution with elevated privileges, potentially leading to a full system compromise.

Reproduction

The vulnerability can be reproduced by placing an executable file in the unquoted service path of the TravExtensionHostSvc service. Once the executable is in place, the service can be started, which will execute the malicious payload with LocalSystem privileges.

Added: Jan 21, 2026, 7:28 PM
Updated: Jan 21, 2026, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.