VYPR
Critical severity9.8NVD Advisory· Published Mar 21, 2026· Updated Apr 21, 2026

CVE-2019-25568

CVE-2019-25568

Description

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

Affected products

1
  • cpe:2.3:a:microvirt:memu:*:*:*:*:*:*:*:*
    Range: <=6.0.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.