Description
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.
Published: 2026-10-08
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from an incorrect authorization mechanism in the phsvc helper's ALPC port. A local user can connect from any Authenticode‑signed process, and the helper accepts the connection without proper verification. Once connected, the attacker can invoke privileged APIs such as PhSvcApiCreateService to load code into a Microsoft‑signed host like rundll32.exe and execute it with SYSTEM privileges. This flaw effectively allows local code execution with elevated rights and falls under CWE‑863.

Affected Systems

System Informer software, produced by winsiderss, is affected on all releases prior to 4.0.26241.138. Users running these earlier versions are susceptible to the unauthorized access described above.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, indicating high severity. EPSS information is unavailable, and the issue is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been reported. Nonetheless, the attack vector is local, requiring an attacker to be able to launch an Authenticode‑signed process such as rundll32.exe on the system. By establishing an ALPC connection to SiSvcApiPort and calling PhSvcApiCreateService, an attacker can achieve code execution as SYSTEM, providing complete control over the affected machine.

Generated by OpenCVE AI on October 8, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade System Informer to version 4.0.26241.138 or newer, which removes the improper authorization check.
  • If immediate upgrade is not possible, restrict execution of Authenticode‑signed host processes like rundll32.exe using AppLocker or similar controls to prevent arbitrary signed binaries from connecting to SiSvcApiPort.
  • Implement monitoring of ALPC traffic to SiSvcApiPort and watch for calls to PhSvcApiCreateService; alert on suspicious local activity.

Generated by OpenCVE AI on October 8, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.
Title System Informer before 4.0.26241.138 Incorrect Authorization in phsvc ALPC Port
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T20:15:56.603Z

Reserved: 2026-10-08T20:02:31.398Z

Link: CVE-2026-107782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:17:53.227

Modified: 2026-10-08T21:34:48.800

Link: CVE-2026-107782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses