Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wacom
Wacom wtabletservice |
|
| Vendors & Products |
Wacom
Wacom wtabletservice |
Wed, 04 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots. | |
| Title | Wacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-04T23:15:55.439Z
Updated: 2026-02-04T23:15:55.439Z
Reserved: 2026-01-06T16:07:08.527Z
Link: CVE-2019-25288
No data.
Status : Received
Published: 2026-02-05T00:15:53.320
Modified: 2026-02-05T00:15:53.320
Link: CVE-2019-25288
No data.