CVE-2019-25266

HIGH

Wondershare Application Framework Service 2.4.3.231 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25266. PoCs published by chuyreds.

AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in Wondershare Application Framework Service 2.4.3.231. It includes service information and commands to identify the vulnerable service but does not contain exploit code.

Description

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the service's execution context.

Exploits (1)

exploitdb WRITEUP
by chuyreds · textlocalwindows
https://www.exploit-db.com/exploits/47617

This is a writeup describing an unquoted service path vulnerability in Wondershare Application Framework Service 2.4.3.231. It includes service information and commands to identify the vulnerable service but does not contain exploit code.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Theoretical
Target: Wondershare Application Framework Service 2.4.3.231
Auth required
Prerequisites: Local access to the target system · Service with unquoted path running with elevated privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47617
Various Sources product
https://www.wondershare.com/
Various Sources product
https://www.wondershare.com/drfone/

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Wondershare/Wondershare Application Framework Service 2.4.3.231
Published Feb 06, 2026
Tracked Since Feb 18, 2026