CVE-2021-47945 - CVE House
Back to Database
Status published High CVE-2021-47945

Argus Surveillance DVR 4.0 Unquoted Service Path Privilege Escalation

Vulnerability Description

Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47945

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Salman Asad (@deathflash1411) a.k.a LeoBreaker

Affected Vendor

Affected Software

Argus Surveillance DVR
Vulnerable Versions:
Argus Surveillance DVR 4.0

Timeline

Official Publish: May 10th, 2026
Last Modified: May 11th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)