CVE-2019-25288 PUBLISHED

Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path

Assigner: VulnCheck
Reserved: 06.01.2026 Published: 04.02.2026 Updated: 04.02.2026

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Wacom
Product Wacom WTabletService
Versions
  • Version 6.6.7-3 is affected

Credits

  • Marcos Antonio León (psk) finder

References

Problem Types

  • Unquoted Search Path or Element CWE