CVE-2026-107782

Source
https://cve.org/CVERecord?id=CVE-2026-107782
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107782.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107782
Published
2026-10-08T20:15:56Z
Modified
2026-10-10T07:05:59Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
System Informer before 4.0.26241.138 Incorrect Authorization in phsvc ALPC Port
Details

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107782.json"
}
References

Affected packages

Git / github.com/winsiderss/systeminformer

Affected ranges

Type
GIT
Repo
https://github.com/winsiderss/systeminformer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.0.26241.138"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.36
v2.37
v2.38
v2.39
v3.*
v3.2.25011.2103

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107782.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "102537763470675618735444836400962141398",
                "8491425862906997390725707905536031772",
                "119926764025706016331206499929844005996",
                "10094958896107992004478195062904096511",
                "232878032832991502399410456463485550765",
                "219862650869239223348896571713624009111",
                "275998744006781655419786741456458108788",
                "267144794652222236580966042635053765741",
                "194304126503796136704697197573940933099"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107782-09bf4c60",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/include/phsvc.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "71421605447993449281177291147104663514",
            "length": 558
        },
        "id": "CVE-2026-107782-2660c473",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/phsvc/svcclient.c",
            "function": "PhSvcCreateClient"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "72044434239435832369510682558870193910",
                "63532832477688503553131794236377729896",
                "206560254616188147311860423851821000644",
                "98670148844619430439601977261420850486",
                "299101232145299749149168685940644940451",
                "25525684924749521281101660612661110430",
                "184223296579580795055754000907926636675",
                "336625068153993051340544129082807403561",
                "80091070376049459573222656479773513281",
                "30077943980061324038817059272636585456",
                "142565197339510067490179660527837127003",
                "185838913617115372116330761348647136482",
                "243348269302346371338628338944470092156"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107782-2cad08c4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/phsvc/svcclient.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "214589248436484038752947708242107059322",
            "length": 234
        },
        "id": "CVE-2026-107782-3db180f4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/phsvc/svcclient.c",
            "function": "PhSvcpClientDeleteProcedure"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "82686100719939983951231066652985367357",
            "length": 2462
        },
        "id": "CVE-2026-107782-4b0e7eaf",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/phsvc/svcapiport.c",
            "function": "PhSvcHandleConnectionRequest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "319992429659068076809199863569789016473",
                "22981877468212217927599862561632992695",
                "21253168246475357481928622012357861198",
                "139759425631897494938715281818356651255",
                "46668076527353247506271683776752564032",
                "174356933680233909554136006759762494215",
                "311639789211041749632066452925518229250",
                "102122345620995237878026490390691149770",
                "53073905236833912507689395603224159044",
                "337731977553263612284123907558460866405",
                "162754588386555932300868463986637007399",
                "276891089695104269518086418328615630930",
                "133730883259440988969012228054539145047",
                "51556107845884704662368553698515820716",
                "11965376552481300834339595500508453777",
                "37074577388205603367976130494534093344",
                "269803136241799386211262224585664188074",
                "42807858931471348510179974427752093636",
                "230621383460483427858935449236485369467",
                "209113711874777094495954321445398610082"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107782-512234b7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/99a0d28e091878967a804ac9ea2fe22f2c1fdadb",
        "target": {
            "file": "kphlib/kphdyn.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "202703392747627769297229901621223627051",
                "328949382258521722975832571938757443737",
                "204282421377581421226021284277312794174",
                "35027525003634397941304008831366476753",
                "124858689228214304161291076817982507443",
                "282224902209998897740542778499901753673",
                "37990109197818420879463453264813752341",
                "338263721320038855205065323528193882269",
                "61819990473318377382150420548816106172",
                "275065852636022007878762393273258514498",
                "48141442924096077738287373623163519047",
                "19017499035083786762214060654574320584",
                "62155713104127652526235661983467538814",
                "129813147370187017878335079857097349327",
                "195299614292427185262902323546556163367",
                "179310710624011069589749447018632707808",
                "80191873034854088570722578041364459331",
                "81499800368870156704858316550797591466",
                "272018794757338523279082926481023019031",
                "265162536386382306102781401742161517155",
                "271313984530002691120500604840668307431",
                "219395139960454912064814692506792329019",
                "318655143423520010887835708052244626743",
                "231321149312127869066089919501778488686",
                "138803830943387423405928438213962573794",
                "45366310340979499575025223604498377129",
                "8349446735506950978076625702006067597",
                "117262245673804241595249911666499713438",
                "151711868831023905567857276429988303691",
                "54331010325950191170388368174938498413",
                "149483930927297095535925621924209406898",
                "269525279837075834487130334517384708975",
                "310978219191742778474591455287108624875",
                "252622465720185313618840303430700243006",
                "59269093725317892749602757181110024301",
                "165242677714567523326438520097549052982",
                "8204649828507804103772824856945835629",
                "133949630224761493143287906607102364285",
                "64921217363155502836981545938013401998",
                "296874337753564551618612310179405831439",
                "24707401398469579782756718807038547319",
                "74051648040177745002090527212092965390",
                "309643395813302117964965007051877564363",
                "270001878098165281244629109735504239597",
                "151711868831023905567857276429988303691",
                "185817840416814564780721861242729337418",
                "148584350698100968391092985527343048872",
                "179394977639567407031307770222137426879",
                "73661703526838616203085608225019736666",
                "261086130155619468468409222943333690829",
                "12662339364124997906939342291247389062",
                "173032850964763716082455515209181662682",
                "45366310340979499575025223604498377129",
                "8349446735506950978076625702006067597",
                "117262245673804241595249911666499713438",
                "151711868831023905567857276429988303691",
                "40131699992858130544504947646146946266",
                "339897973022122874333553315120917478130",
                "278455121814519381032721971969514809065",
                "4160374982318441073491012268815283890",
                "34048590088680673068740923615011164945",
                "254915212450056467040337992113940603113",
                "175603214753288411223643137115155293421",
                "151711868831023905567857276429988303691"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107782-d35469c4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f",
        "target": {
            "file": "SystemInformer/phsvc/svcapiport.c"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:05:59Z"