Cyber Resilience

CVE-2022-50904

HighPublic PoC

Published: 13 January 2026

Published
13 January 2026
Modified
15 April 2026
KEV Added
Patch
CVSS Score v4 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0013 3.1th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2022-50904 is a high-severity Unquoted Search Path or Element (CWE-428) vulnerability in Wondershare UBackit (inferred from references). Its CVSS base score is 8.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Path Interception by Unquoted Path (T1574.009); ranked at the 3.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 CM-6 (Configuration Settings) and SI-2 (Flaw Remediation).

Deeper analysis

CVE-2022-50904 is an unquoted service path vulnerability (CWE-428) in Wondershare UBackit version 2.0.5, specifically affecting the wsbackup service. This flaw enables local users to potentially execute arbitrary code with elevated system privileges, as attackers can exploit the unquoted path to inject malicious executables that run with LocalSystem permissions during service startup. The vulnerability carries a CVSS v3.1 base score of 8.4 (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), highlighting its high severity due to low attack complexity and no required privileges.

A local attacker with access to the system can exploit this vulnerability by placing a malicious executable in a directory that the system searches before the legitimate wsbackup service binary, leveraging the unquoted service path. When the wsbackup service starts, it executes the attacker's binary instead, granting LocalSystem-level privileges. This allows the attacker to achieve high impacts on confidentiality, integrity, and availability, potentially leading to full system compromise.

Advisories and references, including a proof-of-concept exploit on Exploit-DB (https://www.exploit-db.com/exploits/50758) and a detailed analysis from VulnCheck (https://www.vulncheck.com/advisories/wondershare-ubackit-wsbackup-unquoted-service-path), document the issue. The vendor's site (https://www.wondershare.com/) may provide additional guidance, though specific patch details are not specified in available information.

EU & UK References

Vulnerability details

Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the wsbackup service to inject malicious executables that would run with…

more

LocalSystem permissions during service startup.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1574.009 Path Interception by Unquoted Path Stealth
Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.
Why these techniques?

Direct match to unquoted service path enabling path interception for privilege escalation to LocalSystem via existing Windows service.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2020-36928Shared CWE-428
CVE-2023-54336Shared CWE-428
CVE-2020-37048Shared CWE-428
CVE-2019-25306Shared CWE-428
CVE-2020-36979Shared CWE-428
CVE-2020-36929Shared CWE-428
CVE-2020-37017Shared CWE-428
CVE-2021-47859Shared CWE-428
CVE-2019-25309Shared CWE-428
CVE-2021-47790Shared CWE-428

Affected Assets

Wondershare
UBackit
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Establishes and enforces secure configuration settings for services, including properly quoting executable paths to directly prevent exploitation of unquoted service path vulnerabilities.

prevent

Requires identification, reporting, and timely remediation of flaws such as unquoted service paths through patching or reconfiguration to eliminate the vulnerability.

prevent

Enforces least privilege for service accounts, limiting the scope of privileges gained if a malicious executable is run via the unquoted service path.

References