CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.megatec.com.tw/software-download/ |
|
History
Wed, 26 Nov 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges. | |
| Title | Insecure permissions in configuration directory (C:\\usr) | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Gridware
Published:
Updated: 2025-11-26T01:20:13.348Z
Reserved: 2025-11-26T01:02:56.464Z
Link: CVE-2025-66265
No data.
Status : Received
Published: 2025-11-26T01:16:10.173
Modified: 2025-11-26T01:16:10.173
Link: CVE-2025-66265
No data.
OpenCVE Enrichment
No data.