CVE-2025-59888Medium· 6.7▾ SunlitImproper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the
file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
ups_companion < 3.0Upgrade past the affected range:
ups_companion 3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67450High· 7.8Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC wh…
CVE-2024-58288NoneGenexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration
CVE-2021-47792High· 7.8Remote Mouse 4.002 - Unquoted Service Path
CVE-2025-66271Medium· 6.7Clone for Windows provided by ELECOM CO.,LTD
CVE-2021-47822High· 7.8DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
CVE-2025-71326High· 7.8AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges