CVE-2026-8148
NAVER MYBOX Explorer Privilege Escalation via Registry Manipulation
Publication date: 2026-05-08
Last updated on: 2026-05-08
Assigner: Naver Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| naver | mybox_explorer | to 3.0.11.160 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in NAVER MYBOX Explorer for Windows versions before 3.0.11.160. It allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM by manipulating the Windows registry. The root cause is improper privilege checks within the software.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain SYSTEM-level privileges on the affected Windows system. This means they could execute code with the highest level of permissions, potentially leading to full control over the system, unauthorized access to sensitive data, installation of malicious software, or disruption of system operations.