VYPR
Unrated severityNVD Advisory· Published Oct 6, 2022· Updated Aug 3, 2024

CVE-2022-26236

CVE-2022-26236

Description

The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Non-privileged users can overwrite executables/libraries in Beckman Coulter Remisol Advance v2.0.12.1 and prior, leading to privilege escalation.

Vulnerability

The vulnerability exists in the Normand Remisol Advance Launcher component of Beckman Coulter Remisol Advance versions 2.0.12.1 and prior. During installation, the default permissions allow any non-privileged user to overwrite or manipulate executables and libraries that run as the SYSTEM user on Windows [1][2]. This affects the message server service executable (e.g., LauncherService.exe) and associated libraries [2].

Exploitation

An attacker needs low-level access to a workstation, often protected with weak or default credentials [2]. Steps: obtain low-level access, replace the message server service executable or its associated library with a malicious binary, then restart the machine or service. The malicious binary will execute as the SYSTEM/NT Authority user [2].

Impact

Successful exploitation allows the attacker to execute arbitrary code with SYSTEM privileges, leading to full compromise of the workstation and access to sensitive data processed by the Remisol Advance middleware [1][2].

Mitigation

The fix involves correcting the file permissions so that non-privileged users cannot overwrite the service executables [2]. Beckman Coulter has not publicly released a patched version as of the publication date; users should apply the permission fix manually or contact the vendor for guidance [2]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.