CVE-2019-25275
HIGHBartVPN 1.2.2 - Unquoted Service Path Privilege Escalation via BartVPNService
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25275. PoCs published by ZwX.
AI-analyzed exploit summary This exploit demonstrates an unquoted service path vulnerability in BartVPN 1.2.2, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation via executable spoofing.
Description
BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.
Exploits (1)
This exploit demonstrates an unquoted service path vulnerability in BartVPN 1.2.2, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation via executable spoofing.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H