CyberRota Analysis
AI-GeneratedA local privilege escalation vulnerability exists in the Web Vulnerability Scanning Engine of Acunetix for Windows, affecting systems using OpenSSL. Low-privileged local attackers can exploit this flaw by creating a missing directory and placing a malicious file, allowing them to execute arbitrary code with SYSTEM privileges. Organizations utilizing Acunetix on Windows should prioritize patching this vulnerability to mitigate the risk of unauthorized access and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.