nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25747 CVE-2019-25747
HIGH
Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
Record summary
CVE-2019-25747 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Network Inventory AdvisorBrowse Network-Inventory-Advisor / Network Inventory Advisor | CVE List | 5.0.26.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNetwork Inventory Advisor 5.0.26.0 - 'niaservice' Unquoted Service PathExploitDB exploitby Samuel DiazLNot analyzed1 file
References
5ExploitDB-47584exploit
https://www.exploit-db.com/exploits/47584 Official Product Homepageproduct
https://www.network-inventory-advisor.com/ Product Referenceproduct
https://www.network-inventory-advisor.com/download.html VulnCheck Advisory: Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/network-inventory-advisor-unquoted-service-path-privilege-escalation