FreeLAN 2.2 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.
History

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Freelan
Freelan freelan
Vendors & Products Freelan
Freelan freelan

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description FreeLAN 2.2 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.
Title FreeLAN 2.2 - 'FreeLAN Service' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-21T17:27:52.309Z

Updated: 2026-01-22T16:51:36.180Z

Reserved: 2026-01-18T12:35:05.172Z

Link: CVE-2021-47882

cve-icon Vulnrichment

Updated: 2026-01-22T16:46:56.051Z

cve-icon NVD

Status : Received

Published: 2026-01-21T18:16:22.417

Modified: 2026-01-21T18:16:22.417

Link: CVE-2021-47882

cve-icon Redhat

No data.