Executive brief
pcvisit is a remote management tool used by IT professionals to provide technical support. A security flaw in the Windows service client allows a user with low-level access to a computer to overwrite the software's core files. Because this software runs with the highest possible system privileges, an attacker can use this to take full control of the machine, bypass security restrictions, or establish a permanent foothold on the system.
Technical details
The pcvisit RemoteHost module on Windows installs a service binary (pcvisit_service_client.exe) with insecure file permissions that grant 'Modify' and 'Write' access to the 'Everyone' group. A local attacker with low privileges can rename the existing binary and replace it with a malicious executable. Since the pcvisit service is configured to start automatically at boot with NT AUTHORITY\SYSTEM privileges, the attacker's code will execute with full system administrative rights upon the next reboot or service restart. This vulnerability can also be leveraged as a persistence mechanism. The issue was resolved in version 25.12.3.1745 by correcting the default folder and file permissions.
Affected products
- pcvisit Software AG pcvisit RemoteHost 22.6.22.1329 up to (but not including) 25.12.3.1745
Timeline
- 2025-11-25: other: Initial contact with vendor support
- 2025-11-27: other: Vulnerability confirmed by vendor
- 2025-12-08: patched: Patch version 25.12.3.1745 released
- 2026-04-22: disclosed: Public disclosure of vulnerability details
- 2026-04-22: advisory: NVD publication date