PT-2026-79356 · Unknown · Remote Utilities Host
CVSS v4.0
7.3
High
| Vector | AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Remote Utilities Host versions prior to 7.7.3.1
Description
Insecure Access Control Lists (ACLs) are set on all DLL files within the installation directory
C:Program Files (x86)Remote Utilities - Host, granting full control to the built-in Everyone group. A Windows service running as NT AUTHORITYSYSTEM loads DLLs from this location. While files are locked during runtime, a race window occurs when the service is stopped, such as during a crash or software update. This allows a local unprivileged attacker to replace a DLL with a malicious payload, which then executes with system privileges upon service restart. The DLL libasset32.dll was confirmed as actively loaded, and other affected files include eventmsg.dll, libcodec32.dll, vp8encoder.dll, vp8decoder.dll, webmvorbisdecoder.dll, webmvorbisencoder.dll, and webmmux.dll.Recommendations
Update to a version newer than 7.7.3.0.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Utilities Host