216.73.216.197

CVE-2025-15561

· Published 19/02/2026 11:15 · Modified 19/02/2026 15:52

Labels: CVE-2025-15561 2026-02-19551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-15561CWE-269

Essential information

Published
19/02/2026 11:15
Modified
19/02/2026 15:52
Author
Creator
CISA KEV
No
CWE

Description

An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named  WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by the WorkTime monitoring daemon.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
worktime / worktime daemon cpe:2.3:a:worktime:worktime_daemon:*:*:*:*:*:*:*:*

References