CVE-2018-25359
Splinterware System Scheduler Pro 5.12 Privilege Escalation
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.6EPSS 0.2%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
25 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Splinterware · Splinterware System Scheduler Propublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/45072unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →