Home

Description

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

PUBLISHED Reserved 2026-01-06 | Published 2026-02-04 | Updated 2026-02-05 | Assigner VulnCheck




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Unquoted Search Path or Element

Product status

6.6.7-3
affected

Credits

Marcos Antonio León (psk) finder

References

www.exploit-db.com/exploits/47593 (ExploitDB-47593) exploit

www.wacom.com (Wacom Official Homepage) product

www.vulncheck.com/...wtabletservicepro-unquoted-service-path (VulnCheck Advisory: Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path) third-party-advisory

cve.org (CVE-2019-25288)

nvd.nist.gov (CVE-2019-25288)

Download JSON