HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2018-25359 — Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vul...

·Source: NIST NVD

Updated:

Executive Summary

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.

Analysis

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered. CVSS Score: 8.4. Published: 2026-05-25T15:16:18.357.

Indicators of Compromise (1)

CVE (1)
CVE-2018-25359
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats