Security Advisory

CVE-2025-66264

N/A
UNKNOWN

Vulnerability Description

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
Published Date November 26, 2025
Official Source NIST NVD Advisory