Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.

Project Subscriptions

Vendors Products
Assa Abloy Subscribe
Visionline Subscribe
Assaabloy Subscribe
Visionline Subscribe
Microsoft Subscribe
Windows Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

* Right-click on the folder C:\ProgramData\ASSA ABLOY\Visionline\webserver * Select Properties * Select the Security tab * Click Advanced * Click Disable inheritance * Select Convert inherited permissions into explicit permissions on this object * Remove Users from the list

History

Thu, 07 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Assaabloy
Assaabloy visionline
Microsoft
Microsoft windows
CPEs cpe:2.3:a:assaabloy:visionline:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Assaabloy
Assaabloy visionline
Microsoft
Microsoft windows
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Assa Abloy
Assa Abloy visionline
Vendors & Products Assa Abloy
Assa Abloy visionline

Wed, 11 Mar 2026 06:30:00 +0000


Wed, 11 Mar 2026 05:30:00 +0000


Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
Description Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.
Title Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Path
Weaknesses CWE-250
CWE-276
CWE-732
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/AU:Y/R:U/RE:L/U:Clear'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2026-03-11T05:13:30.886Z

Reserved: 2026-02-27T06:40:06.038Z

Link: CVE-2026-3315

cve-icon Vulnrichment

Updated: 2026-03-10T13:51:42.640Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T18:19:01.367

Modified: 2026-05-07T20:41:03.490

Link: CVE-2026-3315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T04:00:09Z

Weaknesses