← back
CVE-2023-53984

HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path

CVSS 8.5 HIGHEPSS 0.2%CWE-428
Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
clevo · HotKey Clipboard

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →