Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jul 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade
Brocade network Advisor |
|
| CPEs | cpe:2.3:a:brocade:network_advisor:5.0.26.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Brocade
Brocade network Advisor |
Mon, 22 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Network-inventory-advisor
Network-inventory-advisor network Inventory Advisor |
|
| Vendors & Products |
Network-inventory-advisor
Network-inventory-advisor network Inventory Advisor |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts. | |
| Title | Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-15T01:24:15.275Z
Reserved: 2026-06-19T13:10:13.910Z
Link: CVE-2019-25747
Updated: 2026-06-22T19:34:09.233Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:36:01Z