PT-2026-97782 · Unknown · Evope Collector

CVE-2026-7169

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

7.5

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Evope Collector versions prior to 1.1.7.13
Description An unchecked search path element allows a local attacker without privileges to perform local privilege escalation. By placing a malicious wtsapi32.dll file in the C:ProgramDataEvope directory, the Evope.Service.exe component loads the DLL without verifying its integrity or origin. Since this component runs with NT AUTHORITYSYSTEM privileges, successful exploitation enables code execution with SYSTEM privileges.
Recommendations Update Evope Collector to version 1.1.7.13 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-7169

Affected Products

Evope Collector