PT-2026-5804 · Netgate · Netgate Data Backup
CVE-2019-25271
·
Publicado
2026-02-04
·
Atualizado
2026-02-05
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGATE Data Backup version 3.0.620
Description
The software contains an unquoted service path vulnerability in its
NGDatBckpSrv Windows service configuration. This allows attackers to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.Recommendations
Apply appropriate quoting to the service path configuration for the
NGDatBckpSrv Windows service.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netgate Data Backup