CVE-2025-66265

MEDIUM

CMService.exe - Privilege Escalation

Title source: llm
STIX 2.1

Description

CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.

Scores

CVSS v4 6.9
EPSS 0.0001
EPSS Percentile 3.0%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (1)
MegaTec Taiwan/ClientMate 6.2.2
Published Nov 26, 2025
Tracked Since Feb 18, 2026