Impact
The vulnerability stems from an incorrect authorization mechanism in the phsvc helper's ALPC port. A local user can connect from any Authenticode‑signed process, and the helper accepts the connection without proper verification. Once connected, the attacker can invoke privileged APIs such as PhSvcApiCreateService to load code into a Microsoft‑signed host like rundll32.exe and execute it with SYSTEM privileges. This flaw effectively allows local code execution with elevated rights and falls under CWE‑863.
Affected Systems
System Informer software, produced by winsiderss, is affected on all releases prior to 4.0.26241.138. Users running these earlier versions are susceptible to the unauthorized access described above.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. EPSS information is unavailable, and the issue is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been reported. Nonetheless, the attack vector is local, requiring an attacker to be able to launch an Authenticode‑signed process such as rundll32.exe on the system. By establishing an ALPC connection to SiSvcApiPort and calling PhSvcApiCreateService, an attacker can achieve code execution as SYSTEM, providing complete control over the affected machine.
OpenCVE Enrichment