Impact
The vulnerability in RealTimes Desktop Service 18.1.4 is an unquoted service path flaw in the rpdsvc.exe binary. It allows a local attacker to place a malicious executable in a directory that is part of the unquoted service path, causing the service to launch that executable with LocalSystem privileges during startup or a reboot. This flaw enables the attacker to execute arbitrary code with system level authority. The weakness is classified under CWE-428, which denotes insecure configuration of a system resource that can lead to privilege escalation.
Affected Systems
RealTimes Desktop Service version 18.1.4 is affected. No other versions are listed as vulnerable. The flaw resides in the system service executable that runs locally on Windows machines where the service is installed.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity for local privilege escalation. EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog, so no publicly known exploitation campaigns are reported. The likely attack vector is local; an attacker with user or application‑level access can exploit the flaw by placing a crafted executable in an unquoted path directory or by renaming an executable to a path that the service will resolve. If successful, the attacker gains LocalSystem rights, potentially compromising the entire host.
OpenCVE Enrichment