CVE-2019-25286 PUBLISHED

_GCafé 3.0 - 'gbClienService' Unquoted Service Path

Assigner: VulnCheck
Reserved: 06.01.2026 Published: 04.02.2026 Updated: 04.02.2026

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Gcafe
Product _GCafé
Versions
  • Version 3.0 is affected

Credits

  • Doan Nguyen (4ll4u) finder

References

Problem Types

  • Unquoted Search Path or Element CWE