WOW21 Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in WOW21 version 5.0.1.9 due to an unquoted service path in the WOW21_Service. This flaw allows local attackers to execute arbitrary code with elevated privileges. Exploitation involves injecting malicious executables into the unquoted binary path, which are then executed with LocalSystem rights when the service starts.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with elevated system privileges, potentially allowing for significant changes to the system or application.

Reproduction

The vulnerability can be reproduced by injecting a malicious executable into the unquoted service path of the WOW21_Service. Once the executable is injected, it will be executed with LocalSystem privileges when the service is started.

Added: Jan 14, 2026, 12:17 AM
Updated: Jan 14, 2026, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.