Impact
A local privilege escalation vulnerability exists in the Logitech Logi Options+ updater service on Windows. A low‑privileged local user can execute arbitrary code with SYSTEM rights, exploiting an access control flaw identified as CWE‑269. With SYSTEM privileges the attacker can install malware, modify system binaries and take full control of the host.
Affected Systems
All installations of Logitech Logi Options+ that contain the legacy updater service are affected. Versions prior to 2.7 are vulnerable; upgrading to 2.7 or later mitigates the issue. No specific sub‑version ranges are listed beyond the 2.7 threshold.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 score of 8.5, indicating a high‑severity impact. The EPSS score is reported as < 1%, showing a low probability of exploitation, and the vulnerability is not enlisted in CISA KEV. The exploit requires no network access; a local attacker with the ability to run applications or scripts can trigger the flaw, making it straightforward to abuse in multi‑user environments.
OpenCVE Enrichment