CVE-2026-24466
MEDIUMOki Electric Industry Co., Ltd. - Privilege Escalation
Title source: llmDescription
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
References (5)
Scores
CVSS v3
6.7
EPSS
0.0002
EPSS Percentile
5.5%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-428
Status
published
Products (3)
Murata Machinery, Ltd./See "References" section
See "References" section
Oki Electric Industry Co., Ltd./See "References" section
See "References" section
Ricoh Company, Ltd./See "References" section
See "References" section
Published
Feb 09, 2026
Tracked Since
Feb 18, 2026