Home

Description

CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

PUBLISHED Reserved 2025-11-26 | Published 2025-11-26 | Updated 2025-11-26 | Assigner Gridware




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

6.2.2
affected

References

www.megatec.com.tw/software-download/

cve.org (CVE-2025-66265)

nvd.nist.gov (CVE-2025-66265)

Download JSON