CVE-2025-10541 Details
Description
iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can create and write to this directory, an attacker can place malicious DLLs or executables in it. Upon service restart, the files are moved to the application’s installation path and executed with SYSTEM privileges, leading to privilege escalation.
A local privilege escalation vulnerability has been identified in iMonitor EAM version 9.6394. The issue arises from a system service that runs with NT AUTHORITY\SYSTEM privileges and includes an insecure update mechanism. This mechanism automatically loads files from a user-writable directory into the application's installation path, where they are executed with elevated privileges. As a result, an attacker can place malicious DLLs or executables in the directory, leading to unauthorized privilege escalation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 25, 2025CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-imonitorsoft-eam/ | CISA-ADP | BundleRemedyTechnical Analysis |
| https://r.sec-consult.com/imonitor | SEC Consult Vulnerability Lab | BundleRemedyTechnical Analysis |
| http://seclists.org/fulldisclosure/2025/Sep/72 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| iMonitorSoft EAM | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 25, 2025 | CVE Modified | CISA-ADP |
| Sep 25, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion