Cyber Resilience

CVE-2021-47896

HighPublic PoC

Published: 23 January 2026

Published
23 January 2026
Modified
15 April 2026
KEV Added
Patch
CVSS Score v4 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0012 2.4th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2021-47896 is a high-severity Unquoted Search Path or Element (CWE-428) vulnerability in Informer (inferred from references). Its CVSS base score is 8.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Path Interception by Unquoted Path (T1574.009); ranked at the 2.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 CM-6 (Configuration Settings) and SI-2 (Flaw Remediation).

Deeper analysis

CVE-2021-47896 is an unquoted service path vulnerability in PDF Complete Corporate Edition 4.1.45, specifically affecting the pdfcDispatcher service. This issue, mapped to CWE-428, arises from an unquoted path in the service binary location, allowing local attackers to potentially execute arbitrary code by placing malicious executables in directories that the service searches prior to locating the legitimate binary. The vulnerability carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and was published on 2026-01-23.

Local attackers with low privileges can exploit this vulnerability through a straightforward attack requiring low complexity and no user interaction. By injecting a malicious executable into an appropriate directory, the attacker tricks the pdfcDispatcher service into running it with elevated LocalSystem privileges, achieving high impacts on confidentiality, integrity, and availability.

Advisories referenced in VulnCheck and Exploit-DB (exploit ID 49558) document the unquoted path flaw and provide proof-of-concept exploitation details. Additional resources include the PDF Complete download and support pages, though no specific patch or mitigation steps are outlined in the core description. Security practitioners should verify vendor updates directly from official channels.

EU & UK References

Vulnerability details

PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that…

more

will be run with elevated LocalSystem privileges.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1574.009 Path Interception by Unquoted Path Stealth
Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.
Why these techniques?

Direct unquoted service path (CWE-428) in pdfcDispatcher enables path interception by placing a malicious binary in an earlier search directory, executed with LocalSystem rights.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2020-36928Shared CWE-428
CVE-2023-54336Shared CWE-428
CVE-2020-37048Shared CWE-428
CVE-2019-25306Shared CWE-428
CVE-2020-36979Shared CWE-428
CVE-2020-36929Shared CWE-428
CVE-2020-37017Shared CWE-428
CVE-2021-47859Shared CWE-428
CVE-2019-25309Shared CWE-428
CVE-2021-47790Shared CWE-428

Affected Assets

Informer
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires secure configuration settings for the pdfcDispatcher service, including quoted executable paths, to directly prevent exploitation of the unquoted service path vulnerability.

prevent

Mandates timely identification, reporting, and remediation of flaws like the unquoted service path in PDF Complete Corporate Edition to eliminate the vulnerability.

prevent

Enforces least privilege for services like pdfcDispatcher, reducing the impact of arbitrary code execution even if the unquoted path is exploited.

References