Impact
The ServerView Agents for Windows contain an incorrect permission assignment for a critical resource that allows a local authenticated attacker to elevate privileges to SYSTEM. This constitutes an access‑control flaw (CWE‑732) that can give an attacker full control of the target server, enabling tampering, data exfiltration, and persistence operations.
Affected Systems
The vulnerability affects Fsas Technologies Inc.’s ServerView Agents for Windows version V11.60.04 and all earlier releases.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, and although an EPSS score is not available, the attack requires only local authentication and can be performed on any server where the agent is installed. As the vulnerability is not listed in the CISA KEV catalog, zero‑day risk is currently unknown, yet the impact of achieving SYSTEM level remains critical.
OpenCVE Enrichment