CVE-2019-25305

HIGH

JumpStart 0.6.0.0 - Code Injection

Title source: llm
STIX 2.1

Description

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.

Exploits (1)

exploitdb WRITEUP
by Roberto Escamilla · textlocalwindows
https://www.exploit-db.com/exploits/47549

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Inforprograma/JumpStart 0.6.0.0
Published Feb 06, 2026
Tracked Since Feb 18, 2026