3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-25633
AIDA64 Extreme General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input through the email preferences and report wizard interfaces. Attackers can inject crafted payloads into the Display name field and Load from file parameter to trigger the overflow and execute shellcode with application privileges.

CVE-2019-25609
Server General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration field that allows local attackers to overwrite structured exception handling pointers. Attackers can inject alphanumeric encoded shellcode through the Log Directory field to trigger an SEH exception handler and execute arbitrary code with application privileges.

CVE-2019-25656
R i386 General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

R i386 3.5.0 contains a local buffer overflow vulnerability in the GUI Preferences dialog that allows local attackers to trigger a structured exception handler (SEH) overwrite by supplying malicious input. Attackers can craft a payload string in the 'Language for menus and messages' field to overwrite SEH records and achieve code execution with calculator or arbitrary shellcode.

CVE-2019-25608
Iperius Backup General
8.6
HIGH
EPSS
0.0%
2019 CWE-520 1 PoC

Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary programs with elevated privileges by creating backup jobs. Attackers can configure backup jobs to execute malicious batch files or programs before or after backup operations, which run with the privileges of the Iperius Backup Service account (Local System or Administrator), enabling privilege escalation and arbitrary code execution.

CVE-2019-25612
Admin-Express General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges.

CVE-2019-25306
BlackMoon FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2019-25266
Wondershare Application Framework Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the service's execution context.

CVE-2019-25267
Wing FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2019-25309
Zilab Remote Console Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25273
IP General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and escalate privileges.

CVE-2019-25287
Adaware Web Companion version General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25272
TexasSoft CyberPlanet General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.

CVE-2019-25274
ProShow Producer General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2019-25288
Wacom WTabletService General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

CVE-2019-25344
MobileGo General
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators group with full system access.

CVE-2019-25302
Launch Manager General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup.

CVE-2019-25345
RTK IIS Codec Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.

CVE-2019-25679
RealTerm: Serial Terminal General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

CVE-2019-25286
_GCafé General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25285
device Controller General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.