CVE-2023-26918 is a critical privilege escalation vulnerability affecting Diasoft File Replication Pro 7.5.0. It allows an unauthenticated attacker to replace a legitimate system file with a malicious executable, which then runs with LocalSystem privileges due to insecure file permissions. This flaw carries a CVSS score of 9.8, indicating a severe impact on confidentiality, integrity, and availability. While not observed in active exploitation, public exploit code exists, and its low EPSS score suggests limited current threat, despite the high FAUCET Risk Score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.5.0CPE matchmatch criteria | cpe:2.3:a:filereplicationpro:file_replication_pro:7.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.