RemoteView Agent for Windows Incorrect Access Permission Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A vulnerability exists in RemoteView Agent for Windows, in versions prior to 8.1.5.2, due to incorrect access permissions in a specific service. This vulnerability allows a non-administrative user on the remote PC to execute arbitrary operating system commands with LocalSystem privileges.

Impact

Exploitation of this vulnerability enables a non-administrative user on the remote PC to execute arbitrary OS commands with LocalSystem privileges.

Remediation

Users are advised to update RemoteView Agent for Windows to version 8.1.5.2, released on February 13, 2025. The software will be updated automatically to this fixed version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.