Local Privilege Escalation in Evope Collector by Unchecked Search Path Element
CVE-2026-7169

7.5HIGH

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-7169?

The Evope Collector software has a local privilege escalation vulnerability due to an unchecked search path element. This issue exists in versions prior to 1.1.7.13 and allows local attackers, without the need for privileges, to execute a malicious Dynamic-Link Library (DLL) by placing a 'wtsapi32.dll' file in 'C:\ProgramData\Evope'. The vulnerable component, 'Evope.Service.exe', operates with NT AUTHORITY\SYSTEM privileges and fails to verify the integrity or origin of the loaded DLL. Successful exploitation can lead to code execution with elevated SYSTEM privileges, thereby facilitating local privilege escalation.

Affected Version(s)

Evope Collector 1.1.6.9.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javier Sanz MartĂ­n
.