Impact
The vulnerability exists in StableBit Scanner 2.6.13.4088, specifically affecting the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe. The misconfigured file permissions allow a local attacker to manipulate the executable’s access rights, potentially enabling the attacker to execute arbitrary code or elevate privileges on the host. This flaw is exploited through local execution alone, and a publicly available exploit has been documented, indicating that the attack may be widely accessible to those with local access.
Affected Systems
The affected vendor and product are StableBit Scanner, version 2.6.13.4088. The vulnerability impacts the ScannerService component of the application, which runs under default system privileges on Windows installations of the scanner.
Risk and Exploitability
With a CVSS score of 8.5, the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity may be limited. However, because the attack vector is local, any user with physical or remote console rights could potentially exploit the mis‑configured permissions. The risk is therefore elevated for systems where the StableBit Scanner service is configured to run with administrative rights or where file permissions are overly permissive for non‑privileged users.
OpenCVE Enrichment