CVE-2025-57227
7.8Kingosoft Technology Ltd · Kingo ROOT
Kingo ROOT v1.5.8.3353 contains an unquoted service path vulnerability, allowing local attackers to escalate privileges by placing a malicious executable in a parent directory.
Executive summary
An unquoted service path vulnerability in Kingo ROOT v1.5.8.3353 poses a high risk of local privilege escalation for affected Windows systems.
Vulnerability
The application utilizes an unquoted service path, which permits a local user with low privileges to execute arbitrary code with elevated system permissions by placing a crafted file in the path hierarchy.
Business impact
Successful exploitation of this flaw allows a local attacker to gain full administrative control over the compromised host. Given the CVSS score of 7.8, this vulnerability represents a significant risk to system integrity and confidentiality, as it facilitates unauthorized access and potential lateral movement within the network.
Remediation
Immediate Action: Since a direct patch is currently unknown, administrators should restrict file system permissions on the affected service directory to prevent unauthorized users from creating files in the parent path.
Proactive Monitoring: Monitor system logs for the execution of unexpected processes or services that originate from directories associated with the Kingo ROOT installation.
Compensating Controls: Ensure that local user accounts follow the principle of least privilege, as this vulnerability requires local access to the system to trigger the escalation.
Exploitation status
Public Exploit Available: Yes, a public exploit is available via ExploitDB (reference entry 51707).
Analyst recommendation
Due to the availability of a public exploit and the high potential for privilege escalation, this vulnerability must be treated with urgency. Organizations should apply restrictive folder permissions to the vulnerable service path immediately and monitor for unauthorized file placement to mitigate the risk of system compromise.