Impact
The vulnerability arises from the use of an insufficiently strong encryption algorithm to protect the configuration of user accounts stored in the built‑in user directory of PcVue projects, versions before 17.0.0. A local attacker who can write to the project files can modify the encrypted user configuration, thereby changing account privileges and ultimately obtaining privileged control of the PcVue application. This flaw is classified as CWE-326 and results in privilege escalation.
Affected Systems
Arcinfo PcVue installations that use any version released prior to 17.0.0 are affected. The weak encryption applies to the built‑in user directory of every PcVue project file, regardless of location. No specific sub‑versions are listed beyond the overall threshold of <17.0.0.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability, yet the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of current exploitation. Successful exploitation requires local access to the PcVue file system and the ability to alter the user directory configuration. Attackers who meet these prerequisites could elevate privileges within the PcVue application. No evidence indicates that this flaw can be abused over the network; the description claims only local attack capability. Applying the published patch removes the weak encryption support and eliminates this attack surface.
OpenCVE Enrichment