Genexus Protection Server Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in Genexus Protection Server version 9.7.2.10, specifically within the 'protsrvservice' Windows service. The issue arises from an unquoted service path, which can be exploited by attackers to execute arbitrary code with elevated LocalSystem privileges. This is achieved by placing malicious executables in certain locations of the file system.

Impact

Exploitation of this vulnerability allows for unauthorized execution of code with high privileges, potentially leading to a full system compromise.

Reproduction

The vulnerability can be reproduced by first confirming the unquoted service path of the 'protsrvservice' using the 'sc qc' command. This will reveal the binary path, which is vulnerable to exploitation. Malicious executables can then be placed in specific locations to be executed by the service with elevated privileges.

Added: Dec 11, 2025, 10:43 PM
Updated: Dec 11, 2025, 10:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.