Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
History

Thu, 26 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mikogo
Mikogo mikogo
CPEs cpe:2.3:a:mikogo:mikogo:5.2.150317:*:*:*:*:*:*:*
Vendors & Products Mikogo
Mikogo mikogo

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Litemanager Team
Litemanager Team mikogo
Vendors & Products Litemanager Team
Litemanager Team mikogo
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Description Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
Title Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-02-11T14:56:51.266Z

Updated: 2026-02-11T21:16:34.582Z

Reserved: 2026-02-10T18:44:39.917Z

Link: CVE-2019-25308

cve-icon Vulnrichment

Updated: 2026-02-11T21:16:31.531Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-11T15:16:09.373

Modified: 2026-02-26T21:26:46.887

Link: CVE-2019-25308

cve-icon Redhat

No data.