HIGH
winsiderss
CVE published 2026-10-08
CVE-2026-107782
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper. This allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process, potentially leading to code execution as SYSTEM. Defenders should assess exposure and prioritize patching to prevent exploitation. The vulnerability exists due to inadequate authorization checks [truncated]