CVE-2019-25306 PUBLISHED

BlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive Path

Assigner: VulnCheck
Reserved: 10.02.2026 Published: 11.02.2026 Updated: 11.02.2026

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Blackmoon
Product BlackMoon FTP Server
Versions
  • Version 3.1.2.1731 is affected

Credits

  • Debashis Pal finder

References

Problem Types

  • Unquoted Search Path or Element CWE