CVE-2019-25308
HIGHMikogo <5.2.2.150317 - Code Injection
Title source: llmDescription
Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
Exploits (1)
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
0.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-428
Status
published
Affected Products (1)
mikogo/mikogo
Timeline
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026