CVE-2026-3315: Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Path
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3315?
CVE-2026-3315 is classified as a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2026-3315?
To fix CVE-2026-3315, ensure that the file permissions for the Visionline service path are properly restricted.
What are the implications of CVE-2026-3315?
CVE-2026-3315 allows attackers to gain unnecessary privileges, potentially leading to unauthorized access and control over the system.
Which versions of ASSA ABLOY Visionline are affected by CVE-2026-3315?
CVE-2026-3315 affects ASSA ABLOY Visionline versions between 1.0 and 1.33.
Is there a workaround for CVE-2026-3315?
A temporary workaround for CVE-2026-3315 may involve manually adjusting permissions on the affected executables until an official patch is available.