CVE-2019-25305
HIGHJumpStart 0.6.0.0 - Unquoted Service Path Privilege Escalation via jswpbapi Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25305. PoCs published by Roberto Escamilla.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in JumpStart 0.6.0.0, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation. The document describes steps to identify and verify the vulnerability but does not include executable exploit code.
Description
JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in JumpStart 0.6.0.0, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation. The document describes steps to identify and verify the vulnerability but does not include executable exploit code.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H