漏洞关键信息 漏洞名称 Acer Launch Manager 6.1.7600.16385 - 'DsiWMIService' Unquoted Service Path 严重性 HIGH 日期 2026-02-06 影响版本 Acer Launch Manager <= 6.1.7600.16385 CVE编号 CVE-2019-25302 CVSS V4向量 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 描述 Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup. 参考链接 ExploitDB-47577 Acer Official Website 发现者 Gustavo Briseño