PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0539 pcvisit CVE debrief

A local privilege escalation vulnerability exists in the pcvisit service binary on Windows due to incorrect default permissions. The service binary is writable by low-privileged users and executes automatically with NT AUTHORITY SYSTEM privileges at boot, allowing an attacker to overwrite it with arbitrary code and gain elevated privileges. The vulnerability affects all versions after 22.6.22.1329 and was remediated in version 25.12.3.1745.

Vendor
pcvisit
Product
pcvisit Remote Host Modul
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-22
Original CVE updated
2026-05-19
Advisory published
2026-04-22
Advisory updated
2026-05-19

Who should care

Windows system administrators managing pcvisit remote access software, security teams responsible for endpoint privilege management, and organizations using pcvisit for remote support or access should prioritize patching this vulnerability to prevent local privilege escalation attacks.

Technical summary

The pcvisit service binary on Windows is installed with overly permissive default permissions that allow low-privileged local users to modify the executable. Because this service runs automatically at system startup with NT AUTHORITY SYSTEM privileges, an attacker can replace the legitimate binary with malicious code to achieve privilege escalation. The vulnerability is classified under CWE-276 (Incorrect Default Permissions) and carries a HIGH severity CVSS score of 8.5.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade pcvisit to version 25.12.3.1745 or later to remediate the vulnerability
  • Review and restrict file system permissions on service binaries to prevent unauthorized modification
  • Implement principle of least privilege for service accounts and file system access controls
  • Monitor for unauthorized modifications to critical service binaries using file integrity monitoring
  • Audit installed versions of pcvisit across Windows endpoints to identify affected systems

Evidence notes

The vulnerability was disclosed via NVD with references to an InfoGuard security advisory and pcvisit release notes. The CVSS 4.0 vector indicates local attack vector with low attack complexity, no user interaction required, and high impact to confidentiality, integrity, and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-0539 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-0539

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-0539 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0539

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.