ZeroHour
Full Disclosurepublished ()ingested

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

highVulnerabilityimportance 45
AI summary · glm-5.3-flash

0day Rubbish Research Team disclosed a CVSS 7.2 local privilege escalation (CWE-250) in Royal Server 5.04.50529.0 to LocalSystem.

Researchers publicly disclosed a local privilege escalation vulnerability in Royal Server 5.04.50529.0, classified as CWE-250 (execution with unnecessary privileges) with a CVSS score of 7.2. The flaw allows escalation to LocalSystem on the execution path without credential override. The disclosure was posted to the Full Disclosure mailing list on September 8, 2026; no patch or CVE id was mentioned in the notice.

  • LPE to LocalSystem without credential override in Royal Server 5.04.50529.0.
  • Classified CWE-250, execution with unnecessary privileges; CVSS 7.2.
  • Disclosed publicly on the Full Disclosure mailing list.
Full article

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Royal Server 5.04.50529.0. Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250) CVSS: 7.2...

This source does not provide full text. Read it at seclists.org.