Impact
A flaw in Evope Collector that allows a local attacker with no elevated rights to place an arbitrary DLL in the software’s data directory. The Evope.Service.exe service runs under the SYSTEM account and loads this DLL without validating its origin or integrity. This results in code execution with SYSTEM privileges, enabling malicious actors to modify, delete, or steal data and to persist on the system. The weakness is an uncontrolled search path element (CWE‑1135).
Affected Systems
The vulnerability affects Evope Collector releases prior to 1.1.7.13, specifically version 1.1.6.9.0 and earlier. The affected component is the Evope.Service.exe Windows service that operates with NT AUTHORITY\SYSTEM privileges.
Risk and Exploitability
The high severity CVSS score of 7.5 classifies this as a significant local privilege escalation. EPSS data is unavailable, so the exact likelihood of exploitation is unknown, but the flaw requires only local access and no special privileges. The vulnerability is not listed in CISA’s KEV catalog. An attacker who can drop a DLL into the designated folder can achieve SYSTEM level code execution with minimal effort, making the issue highly actionable.
OpenCVE Enrichment