Description
Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.
Published: 2026-04-01
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation to SYSTEM
Action: Apply Patch
AI Analysis

Impact

A race condition exists within Lakeside SysTrack Agent that allows a local attacker to elevate privileges to the SYSTEM account. The flaw arises from a concurrency error (CWE-362) where timing inconsistencies in the agent’s internal operations can be exploited to gain full control over the host, execute arbitrary code, and compromise the entire system.

Affected Systems

The vulnerability affects all instances of Lakeside Software’s SysTrack Agent versions earlier than 11.5.0.15. Fixed releases are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15; any system running an earlier version remains exposed.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity for users with local access, and EPSS data is not available. The flaw is not listed in major known exploited vulnerabilities catalogs. Attackers would need local presence to trigger the race condition in the agent service, which runs with SYSTEM privileges.

Generated by OpenCVE AI on April 2, 2026 at 05:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SysTrack Agent to version 11.5.0.15 or later
  • Verify that the agent service runs with the least privilege necessary
  • Monitor event logs for unexpected privilege escalation activity
  • If an upgrade cannot be performed immediately, temporarily disable the agent service until the fix is applied

Generated by OpenCVE AI on April 2, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Lakeside SysTrack Agent Enables Local Privilege Escalation
First Time appeared Lakesidesoftware
Lakesidesoftware systrack Agent
Vendors & Products Lakesidesoftware
Lakesidesoftware systrack Agent

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Lakesidesoftware Systrack Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-01T20:11:43.803Z

Reserved: 2026-04-01T15:39:51.020Z

Link: CVE-2026-35099

cve-icon Vulnrichment

Updated: 2026-04-01T16:12:15.410Z

cve-icon NVD

Status : Deferred

Published: 2026-04-01T16:23:50.953

Modified: 2026-04-27T19:18:46.690

Link: CVE-2026-35099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:17:21Z

Weaknesses