The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
History

Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Megatec
Megatec upsilon2000
Vendors & Products Megatec
Megatec upsilon2000

Wed, 26 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 02:00:00 +0000

Type Values Removed Values Added
Title Unquoted Service path in AutoStart SYSTEM privileged service Unquoted Service path in UPSilon2000V6.0 SYSTEM privilege service

Wed, 26 Nov 2025 01:15:00 +0000

Type Values Removed Values Added
Description The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
Title Unquoted Service path in AutoStart SYSTEM privileged service
Weaknesses CWE-428
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published: 2025-11-26T01:09:51.506Z

Updated: 2025-11-26T16:09:51.264Z

Reserved: 2025-11-26T00:21:58.504Z

Link: CVE-2025-66264

cve-icon Vulnrichment

Updated: 2025-11-26T16:09:38.093Z

cve-icon NVD

Status : Received

Published: 2025-11-26T01:16:10.023

Modified: 2025-11-26T01:16:10.023

Link: CVE-2025-66264

cve-icon Redhat

No data.