VYPR
Unrated severityNVD Advisory· Published Oct 6, 2022· Updated Aug 3, 2024

CVE-2022-26237

CVE-2022-26237

Description

The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Non-privileged users can overwrite executables of the Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior, leading to privilege escalation to SYSTEM.

Vulnerability

The Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior has insecure default file permissions on its executables and libraries. This allows any non-privileged user to overwrite or manipulate files that run as the elevated SYSTEM user on Windows [2]. The issue affects versions up to and including v2.0.12.1 [1][2].

Exploitation

An attacker needs low-level access to a workstation running the vulnerable software. These workstations are often protected with weak, default, or no passwords [2]. The attacker then replaces the ViewerService.exe executable (or any associated library) with a malicious binary. After restarting the machine or the service, the malicious binary runs as NT AUTHORITY\SYSTEM [2].

Impact

Successful exploitation yields full local privilege escalation to the SYSTEM account. The attacker gains complete control over the affected workstation, including the ability to access sensitive data processed by the Remisol Advance middleware [1][2].

Mitigation

Beckman Coulter has not yet disclosed a fixed version or patch in the available references. The vendor recommends correcting the service directory permissions so that non-privileged users cannot overwrite executables, preventing local privilege escalation [2]. Users should ensure strong passwords are enforced on all workstations and apply the principle of least privilege.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.