{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/system-informer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:system_informer:system_informer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-107782"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["System Informer (\u003c 4.0.26241.138)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability"],"_cs_type":"advisory","_cs_vendors":["System Informer"],"content_html":"\u003cp\u003eSystem Informer (formerly Process Hacker) contains an incorrect authorization vulnerability in its helper service, phsvc, tracked as CVE-2026-107782. The vulnerability exists because the phsvc service incorrectly validates the authenticity of processes attempting to connect to its privileged APIs via the SiSvcApiPort. Specifically, the service trusts any process that possesses a valid Authenticode signature, regardless of whether that process is inherently trustworthy or compromised. A local attacker can abuse this by loading malicious code into a legitimate, Microsoft-signed binary such as rundll32.exe. Once the malicious code is running within the signed context, it can establish a connection to SiSvcApiPort and invoke the PhSvcApiCreateService function. This allows the attacker to execute arbitrary code with SYSTEM-level privileges. This flaw impacts all versions of System Informer prior to 4.0.26241.138 and represents a significant privilege escalation vector for local attackers who have already gained low-privileged access to a system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to escalate privileges from a low-privileged user account to the SYSTEM account. This bypasses standard Windows security boundaries, granting the attacker full control over the compromised host. This is critical for post-exploitation activities, including credential dumping, persistence establishment, and disabling security software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate System Informer to version 4.0.26241.138 or later immediately on all endpoints where the software is deployed to address the incorrect authorization flaw in phsvc.\u003c/p\u003e\n","date_modified":"2026-10-08T22:14:33Z","date_published":"2026-10-08T22:14:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-system-informer-privesc/","summary":"System Informer versions prior to 4.0.26241.138 contain an incorrect authorization vulnerability in the phsvc service that allows local attackers to elevate privileges to SYSTEM via privileged API calls.","title":"Privilege Escalation Vulnerability in System Informer phsvc","url":"https://feed.craftedsignal.io/briefs/2026-10-system-informer-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - System Informer","version":"https://jsonfeed.org/version/1.1"}