Security Advisory

CVE-2025-60320

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-29 00:00:00
Last updated 2025-10-30 14:40:19
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The affected service is installed with a path containing spaces and without surrounding quotes. This misconfiguration allows local users to escalate privileges to SYSTEM by placing a malicious executable at C:\Program.exe.