DeepCool DeepCreative Insecure Permissions Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in DeepCool DeepCreative versions through 1.2.7, related to insecure permissions. This flaw allows a local attacker to execute arbitrary code by manipulating a crafted file. The vulnerability arises because an unprivileged user can overwrite a file executed by the NT\SYSTEM account, which runs as a service for DeepCreative.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code with elevated privileges, as the code would run under the NT\SYSTEM account.

Reproduction

To reproduce this vulnerability, an unprivileged user can overwrite a file that is executed by the NT\SYSTEM account as a service for DeepCreative. Once the file is replaced with a crafted version, the arbitrary code can be executed when the service runs the modified file.

Added: Apr 20, 2026, 5:37 PM
Updated: Apr 20, 2026, 5:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
6.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.