---
id: CVE-2021-47822
title: DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
summary: >-
  DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in
  its binary path configuration that allows local attackers to execute code with
  elevated privileges. Attackers can exploit the unquoted path by placing
  malicious …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-428
vendor: Diskboss
product: DiskBoss Service
affected:
  - service 12.2.18
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-01-16T21:01:56.942432Z'
published: '2026-01-16'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:41.397Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2021-47822'
references:
  - url: 'https://www.exploit-db.com/exploits/49899'
    label: ExploitDB-49899
  - url: 'https://www.diskboss.com'
    label: Official Vendor Homepage
  - url: >-
      https://www.vulncheck.com/advisories/diskboss-service-diskbsaexe-unquoted-service-path
    label: >-
      VulnCheck Advisory: DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted
      Service Path
tags:
  - cve.org
epss: 0.00169
epssPercentile: 0.05566
ingestedAt: '2026-10-01T15:48:17.873Z'
---

## Overview

DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level access during service startup.

## Affected

- `service 12.2.18`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
