CVE-2019-25308

Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mikogo:mikogo:5.2.150317:*:*:*:*:*:*:*

History

26 Feb 2026, 21:26

Type Values Removed Values Added
CPE cpe:2.3:a:mikogo:mikogo:5.2.150317:*:*:*:*:*:*:*
References () http://html.tucows.com/preview/518015/Mikogo?q=remote+support - () http://html.tucows.com/preview/518015/Mikogo?q=remote+support - Broken Link
References () https://www.exploit-db.com/exploits/47510 - () https://www.exploit-db.com/exploits/47510 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/mikogo-mikogo-service-unquoted-service-path - () https://www.vulncheck.com/advisories/mikogo-mikogo-service-unquoted-service-path - Third Party Advisory
Summary
  • (es) Mikogo 5.2.2.150317 contiene una vulnerabilidad de ruta de servicio sin comillas en la configuración del servicio de Windows Mikogo-Service. Los atacantes pueden explotar la ruta sin comillas para inyectar y ejecutar código malicioso con privilegios de LocalSystem al colocar archivos ejecutables en ubicaciones de ruta específicas.
First Time Mikogo mikogo
Mikogo

11 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 15:16

Updated : 2026-02-26 21:26


NVD link : CVE-2019-25308

Mitre link : CVE-2019-25308

CVE.ORG link : CVE-2019-25308


JSON object : View

Products Affected

mikogo

  • mikogo
CWE
CWE-428

Unquoted Search Path or Element