PT-2025-48119 · Unknown · Cmservice.Exe

Abdul Mhanni

·

Published

2025-11-26

·

Updated

2025-11-26

·

CVE-2025-66265

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions CMService.exe (affected versions not specified)
Description CMService.exe creates the C:usr directory and its subdirectories with insecure permissions, allowing write access to all authenticated users. This enables attackers to replace configuration files, such as snmp.conf, or hijack DLLs to escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66265

Affected Products

Cmservice.Exe