MilleGPG5 Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in MilleGPG5 version 5.7.2. This vulnerability allows authenticated users to modify service executable files in the MariaDB bin directory. Exploitation involves replacing the mysqld.exe file with a malicious executable, which, upon system restart, executes with elevated privileges.

Impact

Exploitation of this vulnerability allows low-privileged users to gain system-level access by replacing a legitimate service executable with a malicious one that connects back to the attacker's machine.

Reproduction

To reproduce this vulnerability, first generate a malicious executable using a tool like msfvenom, targeting a reverse shell payload. Upload this executable to a web server. On the target machine, download the malicious executable into the MariaDB bin directory, overwriting the original mysqld.exe file. After replacing the file, restart the computer to trigger the execution of the malicious payload, which will open a reverse shell on the attacker's machine.

Added: Jan 15, 2026, 4:57 PM
Updated: Jan 15, 2026, 4:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
4.2
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.