Vendor
System Informer versions prior to 4.0.26241.138 contain an incorrect authorization vulnerability in the phsvc service that allows local attackers to elevate privileges to SYSTEM via privileged API calls.