CVE Database
/

CVE-2025-66266

Back to search

CVE-2025-66266

Published: Nov 26, 2025

Modified: Nov 26, 2025

PUBLISHED

Description

The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to a command; starting and stopping the service to immediately achieve code execution and privilege escalation

VendorProductVersions

MegaTec Taiwan

UPSilon2000V6.0

affected
6.0.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now