CVE-2019-25271: NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25271?
CVE-2019-25271 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2019-25271?
To fix CVE-2019-25271, you should modify the service path to enclose it in quotes to prevent exploitation.
What is the impact of CVE-2019-25271?
CVE-2019-25271 allows attackers to execute arbitrary code with LocalSystem privileges on affected systems.
Which software is affected by CVE-2019-25271?
CVE-2019-25271 specifically affects NETGATE Data Backup version 3.0.620.
Can CVE-2019-25271 be exploited remotely?
CVE-2019-25271 is not a remote vulnerability; it requires local access to exploit.