CVE-2013-10046

HIGH

Agnitum Outpost Internet Security 8.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2013-10046. PoCs published by Metasploit, Ahmad Moghimi, Ahmad Moghimi, juan vazquez, including Metasploit module exploits/windows/local/agnitum_outpost_acs.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Agnitum Outpost Internet Security 8.1 via the acsipc_server named pipe to load arbitrary DLLs and execute code with SYSTEM privileges.

Description

A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. By exploiting a directory traversal weakness in the pipe protocol, an attacker can instruct the service to load a malicious DLL from a user-controlled location. The DLL is then executed in the context of the privileged service.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/28335

This Metasploit module exploits a directory traversal vulnerability in Agnitum Outpost Internet Security 8.1 via the acsipc_server named pipe to load arbitrary DLLs and execute code with SYSTEM privileges.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Agnitum Outpost Internet Security 8.1
No auth needed
Prerequisites: Access to the target system · Agnitum Outpost Internet Security 8.1 installed · Named pipe \\.\pipe\acsipc_server accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Ahmad Moghimi · textlocalwindows
https://www.exploit-db.com/exploits/27282

This exploit demonstrates a privilege escalation vulnerability in Agnitum Outpost Security Suite Pro 8.1 by leveraging a DLL hijacking technique via Regsvr32.exe. The attacker registers a malicious DLL and executes it to escalate privileges from a low-privileged account.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Agnitum Outpost Security Suite Pro 8.1
Auth required
Prerequisites: Access to a low-privileged account on the target system · Ability to place a malicious DLL in a specific directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Ahmad Moghimi, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/agnitum_outpost_acs.rb

This Metasploit module exploits a directory traversal vulnerability in Agnitum Outpost Internet Security 8.1 via the acsipc_server named pipe to load arbitrary DLLs and execute code with SYSTEM privileges. It demonstrates a local privilege escalation (LPE) by writing a malicious DLL to a writable directory and triggering its execution through the vulnerable named pipe.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Agnitum Outpost Internet Security 8.1
No auth needed
Prerequisites: Access to a vulnerable version of Agnitum Outpost Internet Security · Ability to write files to a directory accessible by the acs.exe process
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v4 8.5
EPSS 0.0044
EPSS Percentile 35.0%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-306
Status published
Products (1)
Agnitum Ltd./Outpost Internet Security 8.1
Published Aug 01, 2025
Tracked Since Feb 18, 2026