Description
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
Published: 2026-07-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in ConeXware, Inc Power Archiver version 22.00.11 and earlier allows a remote attacker to obtain higher privileges and execute arbitrary code through the powerarc.exe executable. The flaw grants the ability to run commands or processes with elevated rights, potentially enabling full system compromise. This vulnerability represents improper authorization of privileged operations.

Affected Systems

ConeXware, Inc Power Archiver version 22.00.11 and all earlier releases running on any supported operating platform are affected. The vulnerability is triggered by the powerarc.exe binary bundled with these versions.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8 and has an EPSS score of less than 1%; it is not present in CISA KEV. The flaw permits remote privilege escalation and arbitrary code execution. While the exploitation probability appears low based on EPSS, the potential impact remains high due to the elevated privileges that could be achieved.

Generated by OpenCVE AI on August 4, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an available vendor patch or update Power Archiver to a version that removes the privilege escalation flaw.
  • Limit the execution permissions of powerarc.exe to trusted users only, preventing unauthorized execution.
  • Configure Power Archiver to run under the least privileged account necessary for its operation.

Generated by OpenCVE AI on August 4, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via PowerArc.exe in ConeXware Power Archiver

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via PowerArc.exe in ConeXware Power Archiver

Mon, 27 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Arbitrary Code Execution via powerarc.exe in ConeXware Power Archiver
Weaknesses CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Arbitrary Code Execution via powerarc.exe in ConeXware Power Archiver
Weaknesses CWE-285

Thu, 23 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Conexware
Conexware powerarchiver
Vendors & Products Conexware
Conexware powerarchiver

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
References

Subscriptions

Conexware Powerarchiver
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:13:10.771Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50329

cve-icon Vulnrichment

Updated: 2026-07-24T19:12:39.092Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:17:11.873

Modified: 2026-07-24T20:17:01.797

Link: CVE-2025-50329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure