VYPR

CMService

by Megatec

CVEs (2)

  • CVE-2025-66264HigNov 26, 2025
    risk 0.47cvss epss 0.00

    The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

  • CVE-2025-66265MedNov 26, 2025
    risk 0.45cvss epss 0.00

    CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.