CVE-2026-7169
Received Received - Intake

Unchecked Search Path Element in Evope Collector

Vulnerability report for CVE-2026-7169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’ directory. The ‘Evope.Service.exe’ component, which runs with ‘NT AUTHORITY\SYSTEM’ privileges, loads this DLL without properly verifying its integrity or origin. Successful exploitation could allow code execution with SYSTEM privileges and result in local privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-7169 is a high-severity vulnerability in Evope Collector versions before 1.1.7.13. It involves an unchecked search path element where the application loads a malicious DLL named 'wtsapi32.dll' from 'C:\ProgramData\Evope\' without verifying its integrity. The 'Evope.Service.exe' component runs with SYSTEM privileges and fails to validate the DLL, allowing a local attacker without privileges to place the malicious file and execute code with SYSTEM privileges.

Detection Guidance

Check for the presence of 'wtsapi32.dll' in 'C:\ProgramData\Evope\' on systems running Evope Collector versions prior to 1.1.7.13. Verify the file's integrity and origin. Use process monitoring tools to detect unexpected DLL loads by 'Evope.Service.exe'.

Impact Analysis

This vulnerability allows a local attacker to escalate privileges to SYSTEM level by placing a malicious DLL in a specific directory. Successful exploitation could lead to full system compromise, unauthorized access, or installation of malware. Systems running vulnerable versions of Evope Collector are at risk.

Compliance Impact

This vulnerability could lead to unauthorized code execution with SYSTEM privileges, potentially compromising sensitive data. For GDPR, it may result in unauthorized access to personal data, violating confidentiality and integrity requirements. For HIPAA, it could allow access to protected health information, breaching security rules. Organizations using affected versions must address this to maintain compliance.

Mitigation Strategies

Update Evope Collector to version 1.1.7.13 or later immediately. Remove any untrusted 'wtsapi32.dll' files from 'C:\ProgramData\Evope\'. Restrict write permissions to the directory to prevent unauthorized DLL placement.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart