Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access. | |
| Title | Multiple vulnerabilities in Small HTTP server by Smallsrv | |
| First Time appeared |
Smallsrv
Smallsrv small Http |
|
| Weaknesses | CWE-428 | |
| CPEs | cpe:2.3:a:smallsrv:small_http:3.06.36:*:*:*:*:*:*:* | |
| Vendors & Products |
Smallsrv
Smallsrv small Http |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T13:37:41.179Z
Reserved: 2025-04-16T09:57:04.871Z
Link: CVE-2025-41359
Updated: 2026-03-26T13:37:37.476Z
Status : Received
Published: 2026-03-26T13:16:25.277
Modified: 2026-03-26T13:16:25.277
Link: CVE-2025-41359
No data.
OpenCVE Enrichment
Updated: 2026-03-26T13:54:39Z