Permissions, Privileges, and Access Controls in Endpoint Security for Windows - #VU146528

 

Permissions, Privileges, and Access Controls in Endpoint Security for Windows - #VU146528

Published: August 31, 2026


Vulnerability identifier: #VU146528
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions. A local user can execute arbitrary code with elevated privileges.

Note, this vulnerability was dubbed HardBreacher.


Affected software

Endpoint Security for Windows

Remediation

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins