CVE-2026-23703
7.8Digital Arts Inc. · FinalCode Client
The FinalCode Client installer contains an incorrect default permissions vulnerability, allowing a local low-privileged user to execute arbitrary code with SYSTEM-level privileges.
Executive summary
A local privilege escalation vulnerability in the FinalCode Client installer allows non-administrative users to execute code with SYSTEM privileges, posing a critical security risk.
Vulnerability
This vulnerability stems from incorrect default permissions (CWE-276) within the application installer. A local attacker with low privileges can leverage this flaw to gain SYSTEM-level execution rights on the host machine.
Business impact
Successful exploitation of this vulnerability results in full system compromise, as the attacker gains the highest level of privileges available on the host. Given the CVSS score of 7.8, this represents a significant risk to data confidentiality and integrity, potentially allowing unauthorized actors to install malware, modify system files, or pivot deeper into the corporate network.
Remediation
Immediate Action: Update FinalCode Client to version 5.43R01 or 6.51R01 immediately to resolve the insecure permissions issue.
Proactive Monitoring: Review system audit logs for unusual process executions or unexpected privilege elevation events originating from the local user account scope.
Compensating Controls: Restrict local user access to the installation directory and monitor for unauthorized modifications to the installer files during the deployment process.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a high risk to endpoints running the affected FinalCode Client versions. Organizations should prioritize the deployment of the vendor-provided patches across all managed workstations to prevent local attackers from escalating their privileges to the highest level. Failure to patch may allow a simple user account to take complete control of the affected system.