---
id: CVE-2021-47787
title: >-
  TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple
  system services running with LocalSystem privileges
summary: >-
  TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple
  system services running with LocalSystem privileges. Attackers can place
  malicious executables in specific unquoted path segments to potentially gain
  SYSTEM-leve…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
vendor: totalav
product: totalav
affected:
  - totalav = 5.15.69
published: '2026-01-16'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-47787'
references:
  - url: 'https://www.exploit-db.com/exploits/50314'
    label: disclosure@vulncheck.com
  - url: 'https://www.totalav.com'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/totalav-unquoted-service-path'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/50314'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00257
epssPercentile: 0.15901
ingestedAt: '2026-10-06T22:23:15.910Z'
---

## Overview

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.

## Affected

- `totalav = 5.15.69`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
