Dos nuevos avisos de seguridad

Imported from official source

Advisory

Cybersecurity Classified by Officially

Elemento de ruta de búsqueda sin controlar en Evope Collector Collector versión 1.1.6.9.0, Core: 1.1.3.2.4, Update: 1.1.0.3.6 – Models: Evope.Service.exe y wtsapi32.dll. INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afecta a Evope Collector, plataforma para acelerar la innovación en negocios. La vulnerabilidad ha sido descubierta por Javier Sanz Martín. A esta vulnerabilidad se le ha asignado el siguiente código, puntuación base CVSS v4.0, vector del CVSS y el tipo de vulnerabilidad CWE: CVE-2026-7169: CVSS v4.0: 8.2 | CVSS /AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-427 La vulnerabilidad ha sido solucionada por el equipo de Evope en la versión 1.1.7.13. CVE-2026-7169: vulnerabilidad de tipo elemento de ruta de búsqueda sin controlar en Evope Collector, versiones anteriores a la 1.1.7.13, permite a un atacante local sin privilegios cargar una DLL maliciosa mediante la colocación de un archivo 'wtsapi32.dll' en la ruta 'C:\ProgramData\Evope\'. El componente 'Evope.Service.exe', que se ejecuta con privilegios de 'NT AUTHORITY\SYSTEM', carga dicha DLL sin verificar adecuadamente su integridad o procedencia. La explotación exitosa ...

Read the original at the source: https://www.incibe.es/node/665512

Officially imported this from INCIBE’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
INCIBE — imported from official source
Official source
https://www.incibe.es/rss.xml RSS
Imported
September 24, 2026 11:30
Versions
2 recorded
Identity
665512 at https://www.incibe.es

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.