An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jpn.nec.com/security-info/secinfo/nv26-004_en.html |
|
History
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nec
Nec expressupdate Agent For Windows |
|
| Vendors & Products |
Nec
Nec expressupdate Agent For Windows |
Fri, 26 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Deficiency in ExpressUpdate Agent Enables SYSTEM-Privilege Code Execution |
Fri, 26 Jun 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges. | |
| Weaknesses | CWE-782 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NEC
Published:
Updated: 2026-06-26T04:19:19.204Z
Reserved: 2026-05-18T01:11:09.851Z
Link: CVE-2026-8797
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:35:51Z
Weaknesses