Impact
A local, authenticated user can exploit a vulnerability in the NI-PAL kernel driver to obtain elevated privileges and execute arbitrary code on Microsoft Windows. The flaw, classified under CWE-1285, permits escalation of local privileges, potentially allowing a low-privileged user to gain SYSTEM level access. Once elevated, an attacker could manipulate system state, exfiltrate sensitive data, or disrupt services.
Affected Systems
The vulnerability affects NI-PAL version 26.3.1 and earlier running on Windows platforms. All installations of these affected versions are susceptible until upgraded to a patched release.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. Because the vulnerability is local and requires authentication, external exploitation is limited. EPSS information is unavailable, but the risk remains significant for environments where local privileged users exist. The issue is not currently listed in the CISA KEV catalog, suggesting no publicly known exploits yet, yet the potential impact justifies prompt remediation.
OpenCVE Enrichment