8.5
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This service binary is automatically launched with NT\SYSTEM privileges on boot. This issue affects all versions after 22.6.22.1329 and was fixed in 25.12.3.1745.
AI Analysis
Local Privilege Escalation vulnerability in pcvisit service client due to incorrect default permissions
Basic Information
ID
CVE-2026-0539
Source
NCSC.ch
Published
Apr 22, 2026 at 13:02
Modified
Apr 22, 2026 at 14:09
Affected Product
Vendor
pcvisit
Product
pcvisit Remote Host Modul
Version
22.6.22.1329
Affected Versions
pcvisit pcvisit Remote Host Modul 22.6.22.1329
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
pcvisit
Product
pcvisit Remote Host Modul
Version
all versions after 22.6.22.1329