Impact
An issue in ConeXware, Inc Power Archiver version 22.00.11 and earlier allows a remote attacker to obtain higher privileges and execute arbitrary code through the powerarc.exe executable. The flaw grants the ability to run commands or processes with elevated rights, potentially enabling full system compromise. This vulnerability represents improper authorization of privileged operations.
Affected Systems
ConeXware, Inc Power Archiver version 22.00.11 and all earlier releases running on any supported operating platform are affected. The vulnerability is triggered by the powerarc.exe binary bundled with these versions.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8 and has an EPSS score of less than 1%; it is not present in CISA KEV. The flaw permits remote privilege escalation and arbitrary code execution. While the exploitation probability appears low based on EPSS, the potential impact remains high due to the elevated privileges that could be achieved.
OpenCVE Enrichment