Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Evope team in version 1.1.7.13.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1135 |
Thu, 24 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation. | |
| Title | Uncontrolled Search Path Element in Evope Collector | |
| First Time appeared |
Evope Collector
Evope Collector evope Collector |
|
| CPEs | cpe:2.3:a:evope_collector:evope_collector:1.1.6.9.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Evope Collector
Evope Collector evope Collector |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-24T12:11:48.604Z
Reserved: 2026-04-27T07:40:53.476Z
Link: CVE-2026-7169
Updated: 2026-09-24T12:11:37.385Z
Status : Received
Published: 2026-09-24T12:17:12.973
Modified: 2026-09-24T13:17:11.720
Link: CVE-2026-7169
No data.
OpenCVE Enrichment
Updated: 2026-09-24T13:00:14Z