← volver
CVE-2019-25286

_GCafé 3.0 - 'gbClienService' Unquoted Service Path

CVSS 8.5 HIGHEPSS 0.1%CWE-428
GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Gcafe · _GCafé

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →