Executive brief
The servereye Windows Agent, a monitoring and management tool, contains a security flaw that allows a standard user to gain full administrative control over a computer. By placing a specific file in a folder with weak security settings, an attacker can trick the system into replacing legitimate software with malicious code. This results in a total system compromise, allowing the attacker to access sensitive data or disrupt operations.
Technical details
A local privilege escalation vulnerability exists in the servereye ClientAgentContainerService (Sensorhub) versions 20.15 and earlier. The SE3Recovery service (EmergencyRecoveryService.exe) runs with SYSTEM privileges and monitors '%ProgramData%\ServerEye3\update\' for a trigger file named 'update_available'. Because this directory has insufficient access restrictions, a local standard user can create this file and provide a path to a directory containing malicious JSON instructions. The service then executes UpdaterAction.exe, which performs an unvalidated file copy from the user-controlled source to protected system destinations, such as overwriting service binaries. Full system compromise is achieved when the service automatically restarts the overwritten binary with SYSTEM privileges. The issue is fixed in Installer-Version 20.16.
Affected products
- servereye GmbH Windows Agent (Sensorhub) <= 20.15
Timeline
- 2026-06-23: patched: Rollout of Installer-Version 20.16 began.
- 2026-07-22: advisory: Public disclosure of CVE-2026-14551.