CVE-2026-77827
moderateLocal Privilege Escalation via Weak Permissions in Maono Link
Maono Link 3.8.13 ships a Windows service, MaonoAiServices, that relies on content under C:\ProgramData\Maono without ensuring that directory is protected from modification by ordinary users (CWE-428, uncontrolled search path element; the CNA describes it as improper write privileges). Because the service runs at a higher privilege level than a standard user, any local standard user can tamper with files in that directory and gain elevated privileges when the service acts on the modified content, resulting in local privilege escalation. A successful attacker obtains elevated access on that machine, with high impact to the confidentiality and integrity of the affected system (CVSS 4.0: 8.4 High; availability is not affected). Affected parties are Windows users running Maono Link 3.8.13 or earlier — the companion software for Maono microphones and audio interfaces — and the flaw is fixed in version 4.0.80. There is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at 0.2% (6th percentile), so no exploitation has been observed.
What to do: Upgrade Maono Link to 4.0.80 or later on all Windows hosts where it is installed — check for the MaonoAiServices service and the C:\ProgramData\Maono directory to identify affected machines. As an interim mitigation, tighten the access control list on C:\ProgramData\Maono so standard users cannot write to it. Given EPSS of 0.2%, no KEV listing, and no public PoC, this can be handled in routine patching cycles, prioritizing shared or multi-user workstations where unprivileged local users are present.
| Maono Link (MaonoAiServices Windows service) | 3.8.13 and earlier; fixed in 4.0.80 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
- Weakness
- CWE-428
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.