{"id":"CVE-2026-107782","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-107782","summary":"System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any…","details":"System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.","published":"2026-10-08T20:15:56.603Z","modified":"2026-10-08T20:15:56.603Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f","label":"winsiderss/systeminformer@ce451a2"},"references":[{"type":"FIX","url":"https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f"},{"type":"WEB","url":"https://github.com/winsiderss/systeminformer/blob/v3.2.25011.2103/SystemInformer/phsvc/svcapiport.c#L196-L230"},{"type":"WEB","url":"https://github.com/winsiderss/systeminformer/releases/tag/v4.0.26241.138"},{"type":"WEB","url":"https://github.com/winsiderss/systeminformer"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/system-informer-before-4.0.26241.138-incorrect-authorization-in-phsvc-alpc-port"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-08T20:15:56.603Z"}}