RemoteView Agent for Windows Incorrect Access Permission Vulnerability Allowing Arbitrary Command Execution
Vulnerability
A vulnerability exists in RemoteView Agent for Windows, in versions prior to 8.1.5.2, due to incorrect access permissions in a specific service. This vulnerability allows a non-administrative user on the remote PC to execute arbitrary operating system commands with LocalSystem privileges.
Impact
Exploitation of this vulnerability enables a non-administrative user on the remote PC to execute arbitrary OS commands with LocalSystem privileges.
Remediation
Users are advised to update RemoteView Agent for Windows to version 8.1.5.2, released on February 13, 2025. The software will be updated automatically to this fixed version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
