A high-severity privilege-escalation flaw tracked as CVE-2021-47985 affects SAPSprint 7.60 on Windows by using an unquoted service path in the SAPSprint service configuration. The vulnerable binary path, C:\Program Files\SAP\SAPSprint\sapsprint.exe, can be abused by a local attacker who places a malicious executable in a searched path location, causing Windows to launch attacker-controlled code when the service starts. The service is configured to start automatically and runs as LocalSystem, making successful exploitation a path to full local privilege escalation.
The issue was previously documented in an Exploit-DB entry by Brian Rodriguez, which described testing on Windows 10 Enterprise 64-bit and noted the absence of a CVE at the time. The newer CVE record classifies the bug as not remotely exploitable but rates it High severity, with CVSS 3.1 7.8 and CVSS 4.0 8.5. Recommended mitigation includes quoting the service path, restricting write access in the affected directories, and monitoring for unauthorized executable placement in locations that Windows may search during service startup.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry for CVE-2021-47985 was published describing the SAPSprint 7.60 unquoted service path privilege-escalation vulnerability, rating it High severity and recommending quoting and protecting the service path. The entry states the flaw is local-only and attributes the source to VulnCheck.
Exploit-DB published an entry documenting an unquoted service path vulnerability in SAPSprint 7.60 on Windows that could allow local privilege escalation via path hijacking in the SAPSprint service running as LocalSystem. The entry credits Brian Rodriguez as the discoverer and notes testing on Windows 10 Enterprise 64-bit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.