PT-2025-44347 · Memoq · Memoq+1

Published

2025-10-29

·

Updated

2025-10-29

·

CVE-2025-60320

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions memoQ versions 10.1.13.ef1b2b52aae and earlier
Description memoQ versions 10.1.13.ef1b2b52aae and earlier contain an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The service is installed with a path containing spaces and without surrounding quotes. This misconfiguration allows local users to escalate privileges to SYSTEM by placing a malicious executable at C:Program.exe.
Recommendations memoQ versions prior to 10.1.13.ef1b2b52aae should be updated.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-60320

Affected Products

Memoq
Memoq Auto Update Service