← Retour aux CVEs
CVE-2019-25306
HIGH7.8
Description
BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie2/11/2026
Derniere modification2/11/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-428
References
http://www.tucows.com/preview/222822/BlackMoon-FTP-Server?q=FTP+server(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/47521(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/blackmoon-ftp-server-bmftp-release-unquoted-serive-path(disclosure@vulncheck.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.