CVE-2026-6958
moderateLocal Privilege Escalation to SYSTEM in Acunetix Windows Scanning Engine
Acunetix 25.11.251107123 for Windows is vulnerable to a local privilege escalation flaw (CWE-427, uncontrolled search path element) in its Web Vulnerability Scanning Engine (wvsc.exe), which runs as SYSTEM but does not hardcode the directory path used for OpenSSL-related files. A low-privileged local attacker can create the missing directory, drop a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in arbitrary code execution as SYSTEM and full compromise of the host. Organizations running the named Acunetix for Windows build are affected; because the attack vector is local, remote-only attackers cannot exploit it directly. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.1% probability of exploitation within 30 days.
What to do: Upgrade Acunetix for Windows to a build newer than 25.11.251107123 per vendor guidance (no fixed version number is available in this data). Until patched, restrict interactive logon and untrusted local users on hosts running the scanner, since exploitation requires low-privileged local access, and check for unexpected files in OpenSSL-related directories that wvsc.exe loads. Because successful exploitation grants SYSTEM rights, treat any scanner host with local account compromise as fully compromised.
| Invicti (Acunetix) Acunetix for Windows (Web Vulnerability Scanning Engine, wvsc.exe) | 25.11.251107123 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.
- Weakness
- CWE-427
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.