Access Control Vulnerability in ExpressUpdate Agent for Windows by NEC
CVE-2026-8797
8.5HIGH
What is CVE-2026-8797?
An access control deficiency has been identified in the ExpressUpdate Agent for Windows, which could allow a malicious user to exploit the product. If they gain access, it may lead to arbitrary code execution with SYSTEM privileges, posing a significant risk to the system’s integrity and security. This vulnerability highlights the need for robust security measures to mitigate unauthorized access and protect sensitive data.
Affected Version(s)
ExpressUpdate Agent for Windows 3.24 and prior
