CVE-2019-25292: Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path
Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and gain system-level access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25292?
CVE-2019-25292 is rated as a high severity vulnerability due to its potential for local code execution with elevated privileges.
How do I fix CVE-2019-25292?
To fix CVE-2019-25292, ensure that the service path for Alps HID Monitor Service is properly quoted in the Windows service configuration.
Who is affected by CVE-2019-25292?
CVE-2019-25292 affects systems running Alps HID Monitor Service version 8.1.0.10 or earlier.
What type of vulnerability is CVE-2019-25292?
CVE-2019-25292 is categorized as an unquoted service path vulnerability.
Can CVE-2019-25292 be exploited remotely?
No, CVE-2019-25292 requires local access to the system for exploitation.