CVE-2026-66344 Details
Description
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
A vulnerability allowing arbitrary code execution with SYSTEM privileges has been identified in NetKids iMark, provided by Integrated Systems Technologies, Inc. This issue arises from an uncontrolled search path element vulnerability, where an authenticated attacker can exploit the application’s DLL loading mechanism. The vulnerability affects NetKids iMark versions 5.2.5.0 and earlier.
Users are advised to update to the latest version of NetKids iMark once it becomes available. Until then, the executable path for the 'nkmsgService' Windows service should be manually updated to include quotes, and the installation folder's access permissions should be reviewed to prevent unauthorized file modifications.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Integrated Systems Technologies NetKids iMark | <= V5.2.5.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion