CVE-2025-15561
Essential information
- Published
- 19/02/2026 11:15
- Modified
- 19/02/2026 15:52
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by the WorkTime monitoring daemon.
NVD status
- Status
- Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
- Source
- 551230f0-3615-47bd-b7cc-93e92e730bbf
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| worktime / worktime daemon | cpe:2.3:a:worktime:worktime_daemon:*:*:*:*:*:*:*:* |