Record summary

CVE-2019-25747 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List5.0.26.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBNetwork Inventory Advisor 5.0.26.0 - 'niaservice' Unquoted Service PathExploitDB exploitby Samuel DiazLNot analyzed1 file
ExploitDB

PoC details

References

5