CVE-2019-25568

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microvirt:memu:*:*:*:*:*:*:*:*

History

21 Apr 2026, 16:48

Type Values Removed Values Added
First Time Microvirt
Microvirt memu
Summary
  • (es) Memu Play 6.0.7 contiene una vulnerabilidad de permisos de archivo inseguros que permite a usuarios con pocos privilegios escalar privilegios al reemplazar el ejecutable MemuService.exe. Los atacantes pueden renombrar y sobrescribir MemuService.exe en el directorio de instalación con un ejecutable malicioso, el cual se ejecuta con privilegios de nivel de sistema cuando el servicio se reinicia después de un reinicio del equipo.
CPE cpe:2.3:a:microvirt:memu:*:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/46437 - () https://www.exploit-db.com/exploits/46437 - Exploit, VDB Entry
References () https://www.memuplay.com/ - () https://www.memuplay.com/ - Product
References () https://www.memuplay.com/download-en.php?file_name=Memu-Setup&from=official_release - () https://www.memuplay.com/download-en.php?file_name=Memu-Setup&from=official_release - Product
References () https://www.vulncheck.com/advisories/memu-play-privilege-escalation-via-insecure-file-permissions - () https://www.vulncheck.com/advisories/memu-play-privilege-escalation-via-insecure-file-permissions - Third Party Advisory

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-04-21 16:48


NVD link : CVE-2019-25568

Mitre link : CVE-2019-25568

CVE.ORG link : CVE-2019-25568


JSON object : View

Products Affected

microvirt

  • memu
CWE
CWE-306

Missing Authentication for Critical Function