CVE-2026-32680

7.8

RATOC Systems, Inc. · RAID Monitoring Manager

The installer for RATOC RAID Monitoring Manager for Windows creates insecure directory permissions when a custom installation path is selected, enabling privilege escalation to SYSTEM.

Executive summary

A local privilege escalation vulnerability in RATOC RAID Monitoring Manager allows non-administrative users to execute arbitrary code with SYSTEM privileges.

Vulnerability

This vulnerability involves incorrect default permissions (CWE-276) where custom installation directories are created with weak Access Control Lists. A local authenticated user can leverage these permissions to modify files within the installation folder, leading to arbitrary code execution with the highest possible system privileges.

Business impact

The potential for a local user to achieve SYSTEM level access poses a severe security risk to the integrity and availability of the host machine. With a CVSS score of 7.8, this high-severity flaw could allow an attacker to bypass all OS security boundaries, install persistent backdoors, or compromise sensitive data stored on the affected workstation or server.

Remediation

Immediate Action: Update RATOC RAID Monitoring Manager to version 2.00.009.260220 or later as provided by the vendor.

Proactive Monitoring: Audit existing installations for non-standard directories and verify that the installation folder has restricted access permissions that prevent modification by standard user accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local users, and monitor system logs for unexpected process execution originating from the application installation directory.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the ease with which a local user can escalate to SYSTEM privileges, administrators should prioritize patching all instances of the RATOC RAID Monitoring Manager. Organizations should verify that current installations are not using custom directories that may have been compromised prior to the update.

Sources