Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhgj-xcf6-9r3p

Опубликовано: 26 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.2

Описание

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

EPSS

Процентиль: 4%
0.00018
Низкий

7.2 High

CVSS4

Дефекты

CWE-428

Связанные уязвимости

nvd
2 месяца назад

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

EPSS

Процентиль: 4%
0.00018
Низкий

7.2 High

CVSS4

Дефекты

CWE-428