CVE-2025-66264: Megatec Taiwan Clientmate

High severity, CVSS 7.2. EPSS: 0.1% chance of exploitation in the next 30 days.

The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

Affected products

Published 2025-11-26. Last modified 2026-06-17.