NesterSoft WorkTime Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in NesterSoft WorkTime versions through 11.8.8. This vulnerability allows an attacker to elevate privileges on the local system to NT Authority\SYSTEM by exploiting the update behavior of the WorkTime monitoring daemon. To execute this attack, a malicious executable must be named WTWatch.exe and placed in the C:\ProgramData\wta\ClientExe directory, which is writable by 'Everyone'. Once dropped, the executable is executed by the WorkTime monitoring daemon with elevated privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation to NT Authority\SYSTEM on the local system.

Reproduction

To reproduce this vulnerability, first create a malicious executable that will be executed with elevated privileges. This can be done by writing a C program that includes the desired payload, adding versioning information to the executable, and linking it correctly. Once the executable is created, rename it to WTWatch.exe and place it in the C:\ProgramData\wta\ClientExe directory. The WorkTime monitoring daemon will then execute the dropped executable as NT Authority\SYSTEM, resulting in elevated privileges.

Added: Feb 19, 2026, 7:05 PM
Updated: Feb 19, 2026, 7:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.