Security Advisory
CVE-2025-66264
N/A
UNKNOWN
Vulnerability Description
The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
Published Date
November 26, 2025
Official Source
NIST NVD Advisory