6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25287
Adaware Web Companion version General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25343
NextVPN Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.

CVE-2019-25310
ActiveFax Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative privileges.

CVE-2019-25612
Admin-Express General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges.

CVE-2019-25283
Shrew Soft VPN Client Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.

CVE-2019-25306
BlackMoon FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2019-25302
Launch Manager General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup.

CVE-2019-25309
Zilab Remote Console Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25273
IP General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and escalate privileges.

CVE-2019-25274
ProShow Producer General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2019-25281
NCP_Secure_Entry_Client Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-1019
Windows 10 Version 1703 Windows
8.5
HIGH
EPSS
2.8%
2019 1 PoC

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue has been addressed by changing how NTLM validates network authentication messages.

CVE-2019-25276
Studio General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.

CVE-2019-25286
_GCafé General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25345
RTK IIS Codec Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.

CVE-2019-25271
Data Backup Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.

CVE-2019-25261
AnyDesk Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.

CVE-2019-25275
BartVPN Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.

CVE-2019-25272
TexasSoft CyberPlanet General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.

CVE-2019-25293
Blue Stacks App Player General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.