<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>System Informer - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/system-informer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 22:14:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/system-informer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in System Informer phsvc</title><link>https://feed.craftedsignal.io/briefs/2026-10-system-informer-privesc/</link><pubDate>Thu, 08 Oct 2026 22:14:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-system-informer-privesc/</guid><description>System Informer versions prior to 4.0.26241.138 contain an incorrect authorization vulnerability in the phsvc service that allows local attackers to elevate privileges to SYSTEM via privileged API calls.</description><content:encoded><![CDATA[<p>System Informer (formerly Process Hacker) contains an incorrect authorization vulnerability in its helper service, phsvc, tracked as CVE-2026-107782. The vulnerability exists because the phsvc service incorrectly validates the authenticity of processes attempting to connect to its privileged APIs via the SiSvcApiPort. Specifically, the service trusts any process that possesses a valid Authenticode signature, regardless of whether that process is inherently trustworthy or compromised. A local attacker can abuse this by loading malicious code into a legitimate, Microsoft-signed binary such as rundll32.exe. Once the malicious code is running within the signed context, it can establish a connection to SiSvcApiPort and invoke the PhSvcApiCreateService function. This allows the attacker to execute arbitrary code with SYSTEM-level privileges. This flaw impacts all versions of System Informer prior to 4.0.26241.138 and represents a significant privilege escalation vector for local attackers who have already gained low-privileged access to a system.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local attacker to escalate privileges from a low-privileged user account to the SYSTEM account. This bypasses standard Windows security boundaries, granting the attacker full control over the compromised host. This is critical for post-exploitation activities, including credential dumping, persistence establishment, and disabling security software.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update System Informer to version 4.0.26241.138 or later immediately on all endpoints where the software is deployed to address the incorrect authorization flaw in phsvc.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>vulnerability</category></item></channel></rss>