BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filehorse
Filehorse bartvpn |
|
| Vendors & Products |
Filehorse
Filehorse bartvpn |
Wed, 04 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context. | |
| Title | BartVPN 1.2.2 - 'BartVPNService' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-04T23:15:51.958Z
Updated: 2026-02-05T14:48:55.540Z
Reserved: 2026-01-06T16:07:08.526Z
Link: CVE-2019-25275
No data.
Status : Received
Published: 2026-02-05T00:15:52.053
Modified: 2026-02-05T00:15:52.053
Link: CVE-2019-25275
No data.