Executive brief
Fsas Technologies ServerView Agents for Windows, a server management tool, contains a security flaw in how it manages file or resource permissions. A user who already has basic access to the server can exploit this to gain full administrative (SYSTEM) control over the machine. This could allow an unauthorized person to access sensitive data, modify system settings, or disrupt server operations.
Technical details
A vulnerability classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) exists in Fsas Technologies ServerView Agents for Windows through version V11.60.04. The flaw stems from insecure permissions on critical system resources managed by the agent software. A local attacker with low-level authenticated access can exploit these weak permissions to modify sensitive files or configurations, leading to a full privilege escalation to the SYSTEM account. The vulnerability is exploitable without user interaction. Users are advised to update to the latest version provided by the vendor or apply recommended workarounds.
Affected products
- Fsas Technologies Inc. ServerView Agents for Windows V11.60.04 and earlier
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed via JVN and NVD
- 2026-06-01: advisory