CVE-2026-7169
Uncontrolled Search Path Element in Evope Collector
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation.
| Vendor | evope collector |
| Product | evope collector |
| Published | Sep 24, 2026 |
| Last Updated | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for evope collector evope collector
Be the first to know when new unknown vulnerabilities affecting evope collector evope collector are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Evope Collector / Evope Collector
1.1.6.9.0
References
Credits
Javier Sanz Martín