PT-2025-52702 · Unknown · Sound4 Server Service

CVE-2023-53965

·

Published

2025-12-22

·

Updated

2025-12-23

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 Server Service version 4.1.102
Description SOUND4 Server Service version 4.1.102 contains an unquoted service path issue that may allow local users with limited privileges to execute code with higher system privileges. An attacker can exploit the unquoted binary path by placing malicious code in the system root path, which could then execute with LocalSystem privileges when the service starts.
Recommendations Versions prior to 4.1.102 are not affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53965

Affected Products

Sound4 Server Service