CVE-2026-23703

7.8

Digital Arts Inc. · FinalCode Client

The FinalCode Client installer contains an incorrect default permissions vulnerability, allowing a local low-privileged user to execute arbitrary code with SYSTEM-level privileges.

Executive summary

A local privilege escalation vulnerability in the FinalCode Client installer allows non-administrative users to execute code with SYSTEM privileges, posing a critical security risk.

Vulnerability

This vulnerability stems from incorrect default permissions (CWE-276) within the application installer. A local attacker with low privileges can leverage this flaw to gain SYSTEM-level execution rights on the host machine.

Business impact

Successful exploitation of this vulnerability results in full system compromise, as the attacker gains the highest level of privileges available on the host. Given the CVSS score of 7.8, this represents a significant risk to data confidentiality and integrity, potentially allowing unauthorized actors to install malware, modify system files, or pivot deeper into the corporate network.

Remediation

Immediate Action: Update FinalCode Client to version 5.43R01 or 6.51R01 immediately to resolve the insecure permissions issue.

Proactive Monitoring: Review system audit logs for unusual process executions or unexpected privilege elevation events originating from the local user account scope.

Compensating Controls: Restrict local user access to the installation directory and monitor for unauthorized modifications to the installer files during the deployment process.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a high risk to endpoints running the affected FinalCode Client versions. Organizations should prioritize the deployment of the vendor-provided patches across all managed workstations to prevent local attackers from escalating their privileges to the highest level. Failure to patch may allow a simple user account to take complete control of the affected system.

More Digital Arts Inc. CVEs

Sources