CVE-2019-25283

HIGH

Shrew Soft VPN Client 2.2.2 - Privilege Escalation

Title source: llm

Description

Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.

Exploits (1)

exploitdb WRITEUP
by D.Goedecke · textlocalwindows
https://www.exploit-db.com/exploits/47660

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-428
Status draft

Timeline

Published Feb 05, 2026
Tracked Since Feb 18, 2026