Executive brief
VX Search is an automated file search and data management solution used to categorize and organize large volumes of files. A security flaw in the Server and Enterprise versions allows a user who already has basic access to a computer to gain full administrative control. By placing a specially named file in a specific folder, an attacker can trick the system into running their malicious code with the highest possible privileges when the service restarts.
Technical details
The vulnerability is a classic unquoted service path (CWE-428) affecting the 'VX Search Server' and 'VX Search Enterprise' Windows services. The binary path for these services (C:\Program Files\VX Search Server\bin\vxsrchs.exe) is not enclosed in quotation marks, which allows a local attacker with write permissions to the parent directories to place a malicious executable (e.g., C:\Program.exe) that will be executed instead of the intended service binary. Because these services run with LocalSystem privileges, successful exploitation results in full system compromise. The issue was identified in version 13.5.28; users should update to the latest version (v18.x) where various bugs have been addressed.
Affected products
- Flexense VX Search Server 13.5.28 and earlier
- Flexense VX Search Enterprise 13.5.28 and earlier
Timeline
- 2021-06-16: disclosed: Vulnerability discovered by researcher Brian Rodriguez
- 2021-06-17: other: Exploit code published on Exploit-DB
- 2026-05-16: advisory: CVE record published and enriched by VulnCheck