PT-2026-6733 · Wondershare · Wondershare Application Framework Service

Chuyreds

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2019-25266

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wondershare Application Framework Service version 2.4.3.231
Description An unquoted service path allows local attackers to potentially execute arbitrary code with elevated privileges. This occurs when a service path contains spaces and is not enclosed in quotation marks, enabling attackers to place malicious executables in specific directory locations to hijack the service execution context.
Recommendations Update Wondershare Application Framework Service to a version that fixes the unquoted service path issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2019-25266

Affected Products

Wondershare Application Framework Service