CVE-2025-66265
Last modified
CVE-2025-66265 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-66265?
How severe is CVE-2025-66265?
How do I fix CVE-2025-66265?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6626The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Opti…4.4
- CVE-2025-66260PostgreSQL SQL Injection (status_sql.php) in DB Electronica …6.5
- CVE-2025-66261Unauthenticated OS Command Injection (restore_settings.php) …9.8
- CVE-2025-66262Arbitrary File Overwrite via Tar Extraction Path Traversal i…9.8
- CVE-2025-66263Unauthenticated Arbitrary File Read via Null Byte Injection …7.5
- CVE-2025-66264The CMService.exe service runs with SYSTEM privileges and co…7.2
- CVE-2025-66266The RupsMon.exe service executable in UPSilon 2000 has insec…9.3
- CVE-2025-66269The RupsMon and USBMate services in UPSilon 2000 run with SY…7.1
- CVE-2025-6627A vulnerability has been found in TOTOLINK A702R 4.0.0-B2023…8.8
- CVE-2025-66270The KDE Connect protocol 8 before 2025-11-28 does not correl…4.7
- CVE-2025-66271Clone for Windows provided by ELECOM CO.,LTD. registers a Wi…8.4
- CVE-2025-66273A command injection vulnerability has been reported to affec…7.2
Are you affected by CVE-2025-66265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
