Impact
The vulnerability resides in Acunetix 25.11.251107123’s Web Vulnerability Scanning Engine executable, wvsc.exe. A missing hard‑coded directory path for OpenSSL files allows a low‑privileged user to place a malicious file where the system process expects a legitimate one. When wvsc.exe is executed as SYSTEM, it loads and runs the attacker‑supplied code, giving the local attacker full administrator rights. The flaw is a classic example of a missing path validation weakness described by CWE‑427, enabling arbitrary code execution and compromising system integrity and confidentiality.
Affected Systems
Acunetix Enterprise Web Vulnerability Scanner from Invicti Security Corp. The affected version is 25.11.251107123 for Windows. No other variants or versions are listed in the provided data.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity of exploitation risk. The EPSS score is not available, but the lack of an entry does not diminish the potential immediate risk, especially given the local nature of the attack. The vulnerability is not listed in the CISA KEV catalog, yet the exploitation requirement – simply creating a directory and dropping a crafted file – can be performed by a local attacker who can run programs on the machine. Consequently, systems running the vulnerable version should be considered at high risk of privilege escalation if not patched.
OpenCVE Enrichment