CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.megatec.com.tw/software-download/ |
Configurations
No configuration.
History
26 Nov 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-26 01:16
Updated : 2025-12-01 15:39
NVD link : CVE-2025-66265
Mitre link : CVE-2025-66265
CVE.ORG link : CVE-2025-66265
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
