← Back to overview

Acunetix version 25.11.251107123 for Windows contains a local privilege escalation vulnerability in its Web Vulnerability Scanning Engine (wvsc.exe). The vulnerability stems from a missing hardcoded directory path for OpenSSL-related files. A low-privileged local attacker can exploit this by creating the missing directory and placing a malicious file at the expected path. The SYSTEM-level wvsc.exe process will then load and execute the malicious file, resulting in full privilege escalation to SYSTEM. This represents a significant security risk as it allows attackers to gain the highest level of Windows system privileges. A proof-of-concept has been published and the vulnerability has been disclosed via full disclosure mailing lists.

Affected products

  • Acunetix 25.11.251107123 for Windows
  • wvsc.exe

Related CVE's

  • CVE-2026-6958

Categories

  • Identity & Access
  • Security Tools
  • Zero-Day Vulnerabilities