Cloud Foundry BOSH Windows Stemcell Builder Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM

Vulnerability

A vulnerability exists in BOSH-Ecosystem BOSH Windows Stemcell Builder, specifically in the BOSH.Utils.psm1 file, prior to version 2019.98. This vulnerability allows low-privilege authenticated users to overwrite service_wrapper.exe or bosh-agent.exe. Exploiting this issue can lead to gaining NT AUTHORITY\SYSTEM privileges upon the next service restart or reboot, potentially allowing full control over the host.

Impact

Exploitation of this vulnerability could result in unauthorized users gaining NT AUTHORITY\SYSTEM privileges, allowing them to execute arbitrary commands with system-level rights and control the host machine.

Remediation

Users are advised to upgrade to BOSH Windows Stemcell Builder version 2019.98 or greater.

Added: Jul 9, 2026, 7:22 AM
Updated: Jul 9, 2026, 7:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.