Small HTTP Server 3.06.36 by Smallsrv contains high-severity Windows service path vulnerabilities tracked as CVE-2025-41368 and CVE-2025-41359. Both advisories describe an unquoted service path affecting the executable configuration C:\Program Files (x86)\shttps_mg\http.exe service, which can cause Windows to resolve and launch an attacker-controlled executable from a higher-priority path location instead of the intended service binary.
A successful attack requires local access but could lead to arbitrary code execution, unauthorized system access, or service disruption if a malicious file is planted in the path searched by the service. The published mitigations call for properly quoting the Windows service path, applying available security updates, and restricting physical and network access to affected systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Two high-severity CVEs, CVE-2025-41359 and CVE-2025-41368, were published for Small HTTP Server 3.06.36. The flaws stem from the unquoted Windows service path 'C:\Program Files (x86)\shttps_mg\http.exe service', which could allow a local attacker to achieve arbitrary code execution, unauthorized access, or service disruption.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.