CVE-2025-66264: Megatec Taiwan Clientmate
High severity, CVSS 7.2. EPSS: 0.1% chance of exploitation in the next 30 days.
The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
Affected products
- Megatec Taiwan Clientmate: version 6.2.2 only
Published 2025-11-26. Last modified 2026-06-17.