CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
History

Wed, 14 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Contpaqi
Contpaqi adminpaq
Vendors & Products Contpaqi
Contpaqi adminpaq

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
Title CONTPAQi® AdminPAQ 14.0.0 - Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-13T22:52:03.138Z

Updated: 2026-01-14T15:24:09.078Z

Reserved: 2026-01-11T13:34:26.330Z

Link: CVE-2022-50938

cve-icon Vulnrichment

Updated: 2026-01-14T15:24:06.405Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T23:15:59.057

Modified: 2026-01-14T16:25:12.057

Link: CVE-2022-50938

cve-icon Redhat

No data.