CVE-2025-15561 Details
Description
An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by the WorkTime monitoring daemon.
A local privilege escalation vulnerability has been identified in NesterSoft WorkTime versions through 11.8.8. This vulnerability allows an attacker to elevate privileges on the local system to NT Authority\SYSTEM by exploiting the update behavior of the WorkTime monitoring daemon. To execute this attack, a malicious executable must be named WTWatch.exe and placed in the C:\ProgramData\wta\ClientExe directory, which is writable by 'Everyone'. Once dropped, the executable is executed by the WorkTime monitoring daemon with elevated privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://r.sec-consult.com/worktime | SEC Consult Vulnerability Lab | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-269 | Improper Privilege Management | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| nestersoft worktime | <= 11.8.8 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 23, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | New CVE Received | SEC Consult Vulnerability Lab |