CVE-2025-1789
Received
Received - Intake
Local Privilege Escalation in Genetec Update Service
Publication date: 2026-02-24
Last updated on: 2026-04-26
Assigner: Genetec Inc.
Description
Description
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| genetec | genetec_update_service | to 2.10.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |