Impact
A race condition exists within Lakeside SysTrack Agent that allows a local attacker to elevate privileges to the SYSTEM account. The flaw arises from a concurrency error (CWE-362) where timing inconsistencies in the agent’s internal operations can be exploited to gain full control over the host, execute arbitrary code, and compromise the entire system.
Affected Systems
The vulnerability affects all instances of Lakeside Software’s SysTrack Agent versions earlier than 11.5.0.15. Fixed releases are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15; any system running an earlier version remains exposed.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity for users with local access, and EPSS data is not available. The flaw is not listed in major known exploited vulnerabilities catalogs. Attackers would need local presence to trigger the race condition in the agent service, which runs with SYSTEM privileges.
OpenCVE Enrichment