๐Ÿ” CVE Alert

CVE-2026-14208

UNKNOWN 0.0

Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities Host <=7.7.3.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\SYSTEM loads DLLs from this directory. The DLLs are file-locked at runtime, but a race window exists when the service is stopped (e.g. during a software update or following a crash), during which a local unprivileged attacker can replace a DLL with a malicious payload. Upon service restart, the payload executes as NT AUTHORITY\SYSTEM. The DLL confirmed as actively loaded during testing is libasset32.dll. Additional DLLs in the same directory (eventmsg.dll, libcodec32.dll, vp8encoder.dll, vp8decoder.dll, webmvorbisdecoder.dll, webmvorbisencoder.dll, webmmux.dll) share identical insecure permissions.

CWE CWE-732
Vendor remote utilities pte. ltd.
Product remote utilities host
Published Aug 21, 2026
Last Updated Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for remote utilities pte. ltd. remote utilities host

Be the first to know when new unknown vulnerabilities affecting remote utilities pte. ltd. remote utilities host are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Remote Utilities Pte. Ltd. / Remote Utilities Host
0 โ‰ค 7.7.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
remoteutilities.com: https://www.remoteutilities.com/product/release-notes.php#windows

Credits

Janik Wehrli of InfoGuard Labs