CVE-2019-25272
TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path
TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Tenaxsoft · TexasSoft CyberPlanetWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →