PT-2026-63334 · Unknown · Servereye Client

·

CVE-2026-14551

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions servereye client versions prior to 20.16
Description The servereye client, also known as sensorhub or ClientAgentContainerService, contains a local privilege escalation flaw. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe) runs as SYSTEM and monitors the directory %ProgramData%ServerEye3update for a trigger file named update available. Because of insufficient access restrictions on this directory, a local standard user can create the trigger file and specify a path to a directory containing malicious JSON instructions. The service then executes the utility UpdaterAction.exe with SYSTEM privileges, which parses these instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination, such as overwriting a service binary. This allows for full system compromise when the service automatically restarts the overwritten binary with SYSTEM privileges.
Recommendations Update the servereye client to a version newer than 20.15. Restrict write access to the %ProgramData%ServerEye3update directory to prevent unauthorized users from creating the update available trigger file.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14551

Affected Products

Servereye Client