Vulnerability Description
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/45072
- https://www.splinterware.com
- https://www.vulncheck.com/advisories/splinterware-system-scheduler-pro-privilege
FAQ
What is CVE-2018-25359?
CVE-2018-25359 is a vulnerability with a CVSS score of 8.4 (HIGH). Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can r...
How severe is CVE-2018-25359?
CVE-2018-25359 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25359?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.