CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coolermaster
Coolermaster masterplus |
|
| Vendors & Products |
Coolermaster
Coolermaster masterplus |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot. | |
| Title | CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-14T19:21:29.912Z
Reserved: 2025-12-27T13:53:29.756Z
Link: CVE-2022-50808
No data.
Status : Deferred
Published: 2026-01-13T23:15:50.193
Modified: 2026-04-15T00:35:42.020
Link: CVE-2022-50808
No data.
OpenCVE Enrichment
Updated: 2026-01-14T11:07:51Z
Weaknesses