CVE-2019-25285: Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service Path
Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Alps Pointing-device Controllerto a version that resolves this vulnerability.Fixed in 8.1202.1711.04
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25285?
CVE-2019-25285 is considered a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2019-25285?
To mitigate CVE-2019-25285, update the Alps Pointing-device Controller to the latest version that resolves the unquoted service path issue.
Who is affected by CVE-2019-25285?
CVE-2019-25285 affects users of the Alps Pointing-device Controller version 8.1202.1711.04.
What type of attack does CVE-2019-25285 enable?
CVE-2019-25285 enables local attackers to execute arbitrary code with elevated privileges.
Is there a workaround for CVE-2019-25285?
A temporary workaround for CVE-2019-25285 is ensuring that the service path is properly quoted if the software cannot be updated immediately.