33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25245
DashBoard General
8.5
HIGH
EPSS
0.1%
2019 CWE-732 2 PoCs

Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can exploit the 'M' or 'C' flags for 'Authenticated Users' group to replace the DashBoard.exe binary with a malicious executable.

CVE-2019-25287
Adaware Web Companion version General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25272
TexasSoft CyberPlanet General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.

CVE-2019-25275
BartVPN Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.

CVE-2019-25344
MobileGo General
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators group with full system access.

CVE-2019-25308
Mikogo Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.

CVE-2019-25276
Studio General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.

CVE-2019-25261
AnyDesk Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.

CVE-2019-25293
Blue Stacks App Player General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.

CVE-2019-25310
ActiveFax Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative privileges.

CVE-2019-25281
NCP_Secure_Entry_Client Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-1019
Windows 10 Version 1703 Windows
8.5
HIGH
EPSS
2.8%
2019 1 PoC

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue has been addressed by changing how NTLM validates network authentication messages.

CVE-2019-25307
WorkgroupMail Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2019-25271
Data Backup Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.

CVE-2019-25679
RealTerm: Serial Terminal General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

CVE-2019-25269
Amiti Antivirus Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges by placing executable files in specific directory locations.

CVE-2019-25292
Alps HID Monitor Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and gain system-level access.

CVE-2019-25304
Intelligent Security System SecurOS Enterprise General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\ISS\SecurOS\ to insert malicious code that would execute with system-level permissions during service startup.

CVE-2021-47805
Disk Savvy Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run with elevated LocalSystem privileges.

CVE-2021-47890
LogonExpert General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentially gaining elevated system access during service startup.