<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:acunetix:acunetix:25.11.251107123:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aacunetixacunetix25.11.251107123/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 15:27:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aacunetixacunetix25.11.251107123/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in Acunetix Web Vulnerability Scanning Engine</title><link>https://feed.craftedsignal.io/briefs/2026-09-acunetix-lpe/</link><pubDate>Fri, 04 Sep 2026 15:27:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-acunetix-lpe/</guid><description>Acunetix 25.11.251107123 for Windows is vulnerable to local privilege escalation via DLL hijacking in the Web Vulnerability Scanning Engine (wvsc.exe) due to insecure directory path handling.</description><content:encoded><![CDATA[<p>Acunetix 25.11.251107123 for Windows contains a critical local privilege escalation (LPE) vulnerability in its Web Vulnerability Scanning Engine (wvsc.exe). The issue stems from the application expecting certain OpenSSL-related files to exist in a specific path that is not hardcoded or properly restricted. A low-privileged local user can proactively create the missing directory structure and inject a malicious DLL file into the expected location. When the wvsc.exe process, which executes with SYSTEM privileges, attempts to load these dependencies, it loads the attacker-controlled file instead. This results in arbitrary code execution with SYSTEM-level permissions. This vulnerability, identified as CVE-2026-6958, allows any local attacker to elevate their privileges to full administrative control over the host system.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a low-privileged local user to escalate their permissions to the SYSTEM level on a system running the affected version of Acunetix. This can lead to total system compromise, including the installation of persistent backdoors, data exfiltration, and lateral movement within the network. The vulnerability impacts organizations using Acunetix 25.11.251107123 on Windows platforms.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately: Upgrade Acunetix installations to a version that addresses CVE-2026-6958.</li>
<li>Implement monitoring: Monitor for file creation events in directories where high-privilege applications search for library dependencies.</li>
<li>Restrict permissions: Ensure that standard user accounts do not have write access to system directories or application installation folders where such hijacking can occur.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>windows</category><category>local-exploitation</category></item></channel></rss>