Unrated severityNVD Advisory· Published Feb 4, 2026· Updated Mar 5, 2026
Wing FTP Server 6.0.7 - Unquoted Service Path
CVE-2019-25267
Description
Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.
Affected products
2- Range: =6.0.7
- Wftpserver/Wing FTP Serverv5Range: 6.0.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/47818mitreexploit
- www.vulncheck.com/advisories/wing-ftp-server-unquoted-service-pathmitrethird-party-advisory
- www.wftpserver.commitreproduct
News mentions
0No linked articles in our index yet.