Executive brief
NEC ExpressUpdate Agent for Windows, a tool used for managing system updates, contains a security flaw in how it controls access to its internal functions. A user who already has basic access to a computer running this software could exploit this weakness to gain full administrative control (SYSTEM privileges). This could allow an attacker to take over the machine, install malicious software, or access sensitive data.
Technical details
An access control deficiency exists in NEC ExpressUpdate Agent for Windows (version 3.24 and prior) due to an exposed IOCTL with insufficient access control (CWE-782). A local attacker with low privileges can interact with the affected component to execute arbitrary code. Successful exploitation results in a full privilege escalation to SYSTEM, compromising the integrity, availability, and confidentiality of the host. The vulnerability is triggered locally without requiring user interaction.
Affected products
- NEC Corporation ExpressUpdate Agent for Windows 3.24 and prior
Timeline
- 2026-06-26: advisory: NVD published the CVE record based on NEC Corporation's disclosure.