Security Advisory

CVE-2024-58288

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-11 21:33:58
Last updated 2025-12-18 19:39:32
Assigner VulnCheck
State PUBLISHED

Description

Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.