logo

CVE-2022-24696 - Glance by Mirametrix Privilege Escalation

ID: ad6f19a5-fea8-56c9-b8de-b4c230a0064f

STIX ID: report--ad6f19a5-fea8-56c9-b8de-b4c230a0064f

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-04-25

Date Updated: 2026-05-01

...
...

This report documents a local privilege escalation vulnerability (CVE-2022-24696) in the Mirametrix/Lenovo Glance MaseService where improper service permissions allowed standard Users to change the service binary path; the author demonstrates a proof-of-concept escalation to SYSTEM using RogueWinRM, coordinated disclosure with Lenovo PSIRT, and notes that the issue is fixed in a Microsoft Store version while legacy installations require manual removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.