CVE-2025-5191
An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in a higher-priority directory within the search path. When the Serial Interface service starts, the malicious executable could be run with SYSTEM privileges. Successful exploitation could allow privilege escalation or enable an attacker to maintain persistence on the affected system.
Leer descripción completaMostrar menos
While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality, integrity, or availability within any subsequent systems.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 7.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Impacto secundario
T1547.001Registry Run Keys / Startup Folderpersistence · privilege escalation85 %
Acceso local con privilegios limitados (PR:L, AV:L) ejecutando código malicioso con SYSTEM mediante unquoted search path, logrando escalada de privilegios (VC:H) y persistencia.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-428
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-5191",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-5191",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-08-25T13:48:00.832287Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "psirt@moxa.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 7.3,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "psirt@moxa.com",
"affectedData": [
{
"vendor": "Moxa",
"product": "Utility for DRP-A100 Series",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom",
"lessThanOrEqual": "1.1"
},
{
"status": "unaffected",
"version": "1.2",
"versionType": "custom"
}
],
"platforms": [
"Windows 10 IoT Enterprise LTSC 2021"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Moxa",
"product": "Utility for DRP-A100 Series",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1",
"versionType": "custom"
}
],
"platforms": [
"Windows 11 IoT Enterprise LTSC 2024",
"Windows 11 Professional 2022"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Moxa",
"product": "Utility for DRP-C100 Series",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom",
"lessThanOrEqual": "1.1"
},
{
"status": "unaffected",
"version": "1.2",
"versionType": "custom"
}
],
"platforms": [
"Windows 10 IoT Enterprise LTSC 2021"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Moxa",
"product": "Utility for DRP-C100 Series",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1",
"versionType": "custom"
}
],
"platforms": [
"Windows 11 IoT Enterprise LTSC 2024",
"Windows 11 Professional 2022"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-08-25T08:15:30.047",
"references": [
{
"url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-256421-cve-2025-5191-unquoted-search-path-vulnerability-in-the-utility-for-industrial-computers-(windows)",
"source": "psirt@moxa.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@moxa.com",
"description": [
{
"lang": "en",
"value": "CWE-428"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in a higher-priority directory within the search path. When the Serial Interface service starts, the malicious executable could be run with SYSTEM privileges. Successful exploitation could allow privilege escalation or enable an attacker to maintain persistence on the affected system. While successful exploitation can severely impact the confidentiality, integrity, and availability of the affected device itself, there is no loss of confidentiality, integrity, or availability within any subsequent systems."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad de ruta de búsqueda sin comillas en la utilidad para ordenadores industriales de Moxa (Windows). Debido a la configuración de la ruta sin comillas en la utilidad SerialInterfaceService.exe, un atacante local con privilegios limitados podría colocar un ejecutable malicioso en un directorio de mayor prioridad dentro de la ruta de búsqueda. Al iniciarse el servicio de interfaz serie, el ejecutable malicioso podría ejecutarse con privilegios de SYSTEM. Una explotación exitosa podría permitir la escalada de privilegios o permitir que un atacante mantenga la persistencia en el sistema afectado. Si bien una explotación exitosa puede afectar gravemente la confidencialidad, integridad y disponibilidad del dispositivo afectado, no se produce pérdida de confidencialidad, integridad ni disponibilidad en los sistemas posteriores."
}
],
"lastModified": "2026-06-17T09:47:25.287",
"sourceIdentifier": "psirt@moxa.com"
}