Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.

Project Subscriptions

Vendors Products
Splinterware Subscribe
Splinterware System Scheduler Pro Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splinterware
Splinterware splinterware System Scheduler Pro
Vendors & Products Splinterware
Splinterware splinterware System Scheduler Pro

Mon, 25 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.
Title Splinterware System Scheduler Pro 5.12 Privilege Escalation
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-26T13:19:38.461Z

Reserved: 2026-05-24T13:14:22.106Z

Link: CVE-2018-25359

cve-icon Vulnrichment

Updated: 2026-05-26T13:19:32.775Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T15:16:18.357

Modified: 2026-05-26T19:47:48.987

Link: CVE-2018-25359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T13:00:45Z

Weaknesses