PT-2026-63334 · Unknown · Servereye Client
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
servereye client versions prior to 20.16
Description
The servereye client, also known as sensorhub or ClientAgentContainerService, contains a local privilege escalation flaw. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe) runs as SYSTEM and monitors the directory
%ProgramData%ServerEye3update for a trigger file named update available. Because of insufficient access restrictions on this directory, a local standard user can create the trigger file and specify a path to a directory containing malicious JSON instructions. The service then executes the utility UpdaterAction.exe with SYSTEM privileges, which parses these instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination, such as overwriting a service binary. This allows for full system compromise when the service automatically restarts the overwritten binary with SYSTEM privileges.Recommendations
Update the servereye client to a version newer than 20.15.
Restrict write access to the
%ProgramData%ServerEye3update directory to prevent unauthorized users from creating the update available trigger file.Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Servereye Client