CVE-2019-25288

HIGH

Wacom WTabletService 6.6.7-3 - Code Injection

Title source: llm

Description

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

Exploits (1)

exploitdb WRITEUP
by Marcos Antonio León · textlocalwindows
https://www.exploit-db.com/exploits/47593

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-428
Status draft

Timeline

Published Feb 05, 2026
Tracked Since Feb 18, 2026