Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed in version V3.06.38.


Workaround

No workaround given by the vendor.

History

Thu, 26 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:45:00 +0000

Type Values Removed Values Added
Description Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.
Title Multiple vulnerabilities in Small HTTP server by Smallsrv
First Time appeared Smallsrv
Smallsrv small Http
Weaknesses CWE-428
CPEs cpe:2.3:a:smallsrv:small_http:3.06.36:*:*:*:*:*:*:*
Vendors & Products Smallsrv
Smallsrv small Http
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-03-26T13:37:41.179Z

Reserved: 2025-04-16T09:57:04.871Z

Link: CVE-2025-41359

cve-icon Vulnrichment

Updated: 2026-03-26T13:37:37.476Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-26T13:16:25.277

Modified: 2026-03-26T15:13:15.790

Link: CVE-2025-41359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-26T13:54:39Z

Weaknesses