PatchSiren

Splinterware CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Splinterware CVE published 2026-05-25

CVE-2018-25359

CVE-2018-25359 documents an insecure file permissions vulnerability in Splinterware System Scheduler Pro 5.12 that enables local privilege escalation. The vulnerability stems from overly permissive access controls on the service executable WService.exe within the installation directory. Low-privilege users can rename the legitimate service executable and substitute a malicious replacement; when the servic [truncated]