Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66264

Опубликовано: 26 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

EPSS

Процентиль: 5%
0.00021
Низкий

Дефекты

CWE-428

Связанные уязвимости

github
2 месяца назад

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

EPSS

Процентиль: 5%
0.00021
Низкий

Дефекты

CWE-428