Incorrect Authorization Vulnerability in System Informer by Winsiderss
CVE-2026-107782

8.5HIGH

Key Information:

Vendor

Winsiderss

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107782?

The System Informer software prior to version 4.0.26241.138 has a vulnerability related to incorrect authorization in its phsvc helper. This flaw permits local attackers to exploit privileged APIs by leveraging any Authenticode-signed process. They can inject malicious code into a Microsoft-signed host, such as rundll32.exe, and subsequently connect to SiSvcApiPort. Utilizing the PhSvcApiCreateService function, these attackers can execute code with SYSTEM-level privileges, undermining the security of the affected system.

Affected Version(s)

System Informer 0 < 4.0.26241.138

System Informer 4.0.26241.138

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Ali
.