Insecure permissions in configuration directory (C:\\usr)
Vulnerability Description
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66265
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Abdul Mhanni
More from MegaTec Taiwan
View All →Affected Vendor
MegaTec Taiwan
View all reports →