๐Ÿ” CVE Alert

CVE-2026-107782

HIGH 7.8

System Informer before 4.0.26241.138 Incorrect Authorization in phsvc ALPC Port

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.

CWE CWE-863
Vendor winsiderss
Product system informer
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for winsiderss system informer

Be the first to know when new high vulnerabilities affecting winsiderss system informer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

winsiderss / System Informer
0 < 4.0.26241.138

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f github.com: https://github.com/winsiderss/systeminformer/blob/v3.2.25011.2103/SystemInformer/phsvc/svcapiport.c#L196-L230 github.com: https://github.com/winsiderss/systeminformer/releases/tag/v4.0.26241.138 github.com: https://github.com/winsiderss/systeminformer vulncheck.com: https://www.vulncheck.com/advisories/system-informer-before-4.0.26241.138-incorrect-authorization-in-phsvc-alpc-port

Credits

Muhammad Ali