iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts. | |
| Title | iFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-15T23:25:47.367Z
Reserved: 2026-01-14T14:39:44.740Z
Link: CVE-2021-47803
No data.
Status : Received
Published: 2026-01-16T00:16:24.707
Modified: 2026-01-16T00:16:24.707
Link: CVE-2021-47803
No data.
OpenCVE Enrichment
No data.