CVE-2019-25302: Acer Launch Manager 6.1.7600.16385 - 'DsiWMIService' Unquoted Service Path
Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25302?
CVE-2019-25302 has been classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2019-25302?
Fix for CVE-2019-25302 involves updating Acer Launch Manager to the latest version where the unquoted service path vulnerability is addressed.
What systems are affected by CVE-2019-25302?
CVE-2019-25302 primarily affects Acer Launch Manager version 6.1.7600.16385.
What type of vulnerability is CVE-2019-25302?
CVE-2019-25302 is an unquoted service path vulnerability that allows local users to execute code with elevated privileges.
Can CVE-2019-25302 be exploited remotely?
CVE-2019-25302 requires local access to exploit, thus it cannot be exploited remotely without prior local access.