PT-2026-97782 · Unknown · Evope Collector
CVE-2026-7169
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
7.5
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Evope Collector versions prior to 1.1.7.13
Description
An unchecked search path element allows a local attacker without privileges to perform local privilege escalation. By placing a malicious
wtsapi32.dll file in the C:ProgramDataEvope directory, the Evope.Service.exe component loads the DLL without verifying its integrity or origin. Since this component runs with NT AUTHORITYSYSTEM privileges, successful exploitation enables code execution with SYSTEM privileges.Recommendations
Update Evope Collector to version 1.1.7.13 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Evope Collector