794 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25285
device Controller General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.

CVE-2019-25345
RTK IIS Codec Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.

CVE-2019-25274
ProShow Producer General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2019-25273
IP General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and escalate privileges.

CVE-2019-25309
Zilab Remote Console Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25306
BlackMoon FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2019-25612
Admin-Express General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges.

CVE-2019-25283
Shrew Soft VPN Client Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.

CVE-2019-25288
Wacom WTabletService General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

CVE-2019-25231
devolo dLAN Cockpit General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows local non-privileged users to potentially execute arbitrary code. Attackers can exploit the insecure service path configuration by inserting malicious code in the system root path to execute with elevated privileges during application startup or system reboot.

CVE-2019-25266
Wondershare Application Framework Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the service's execution context.

CVE-2019-25245
DashBoard General
8.5
HIGH
EPSS
0.1%
2019 CWE-732 2 PoCs

Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can exploit the 'M' or 'C' flags for 'Authenticated Users' group to replace the DashBoard.exe binary with a malicious executable.

CVE-2019-25287
Adaware Web Companion version General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25272
TexasSoft CyberPlanet General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.

CVE-2019-25275
BartVPN Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.

CVE-2019-25344
MobileGo General
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators group with full system access.

CVE-2019-25308
Mikogo Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.

CVE-2019-25276
Studio General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.

CVE-2019-25261
AnyDesk Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.

CVE-2019-25293
Blue Stacks App Player General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.