📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Pharmaceutical HIGH 1h Global vulnerability Technology, Artificial Intelligence CRITICAL 1h Global vulnerability Information Technology CRITICAL 1h Global phishing Gaming and Entertainment HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global phishing Law Enforcement, Cybercrime HIGH 2h Global vulnerability Artificial Intelligence MEDIUM 3h Global vulnerability Government CRITICAL 3h Global data_breach Government HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 4h Global data_breach Pharmaceutical HIGH 1h Global vulnerability Technology, Artificial Intelligence CRITICAL 1h Global vulnerability Information Technology CRITICAL 1h Global phishing Gaming and Entertainment HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global phishing Law Enforcement, Cybercrime HIGH 2h Global vulnerability Artificial Intelligence MEDIUM 3h Global vulnerability Government CRITICAL 3h Global data_breach Government HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 4h Global data_breach Pharmaceutical HIGH 1h Global vulnerability Technology, Artificial Intelligence CRITICAL 1h Global vulnerability Information Technology CRITICAL 1h Global phishing Gaming and Entertainment HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global phishing Law Enforcement, Cybercrime HIGH 2h Global vulnerability Artificial Intelligence MEDIUM 3h Global vulnerability Government CRITICAL 3h Global data_breach Government HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 4h
Vulnerabilities

CVE-2021-47945

High
CWE-428 — Weakness Type
Published: May 10, 2026  ·  Modified: May 17, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.

🤖 AI Executive Summary

CVE-2021-47945 is a local privilege escalation vulnerability in Argus Surveillance DVR 4.0 affecting the DVRWatchdog service through an unquoted service path. Attackers with local access can place malicious executables in Program Files directories to achieve LocalSystem privilege execution. While no public exploit exists and patching is unavailable, this poses significant risk to organizations using legacy DVR systems, particularly in critical infrastructure and surveillance operations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 13, 2026 22:41
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations operating Argus DVR systems face elevated risk, particularly in: (1) Banking sector security operations centers (SOCs) using DVR for physical security monitoring; (2) Government facilities and critical infrastructure (ARAMCO, SEC, airports) relying on legacy surveillance; (3) Healthcare institutions with DVR-based access control; (4) Telecom providers (STC, Mobily) using DVR for facility monitoring. The vulnerability enables insider threats and lateral movement post-compromise, especially dangerous in environments where DVR systems have network access to operational technology (OT) networks.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Critical Infrastructure Energy (ARAMCO, utilities) Healthcare Telecommunications (STC, Mobily) Transportation and Airports Security Operations Centers
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all Argus Surveillance DVR 4.0 deployments across your organization
2. Restrict local access to DVR systems through physical security controls and access management
3. Implement principle of least privilege for user accounts with local DVR access
4. Monitor DVR system logs for suspicious service restarts or binary modifications

Compensating Controls (No Patch Available):
5. Apply filesystem permissions: Remove write access to Program Files directories for non-administrative users
6. Implement AppLocker/Windows Defender Application Control to whitelist only legitimate DVR binaries
7. Disable DVRWatchdog service if not operationally required; use alternative monitoring solutions
8. Isolate DVR systems on segregated network segments with strict ingress/egress controls
9. Deploy Host-Based Intrusion Detection (HIDS) to monitor Program Files for unauthorized executable creation
10. Consider upgrading to modern surveillance solutions with security-by-design architecture

Detection Rules:
- Monitor for file creation in C:\Program Files\ with .exe extension by non-system accounts
- Alert on DVRWatchdog service restart events followed by new process execution
- Track modifications to service binary paths in registry (HKLM\SYSTEM\CurrentControlSet\Services\DVRWatchdog)
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع نشرات Argus Surveillance DVR 4.0 عبر مؤسستك
2. تقييد الوصول المحلي لأنظمة DVR من خلال الضوابط الأمنية المادية وإدارة الوصول
3. تطبيق مبدأ أقل امتياز لحسابات المستخدمين التي لديها وصول محلي إلى DVR
4. مراقبة سجلات نظام DVR للبحث عن إعادة تشغيل الخدمة أو تعديلات ثنائية مريبة

الضوابط البديلة (لا يوجد تصحيح متاح):
5. تطبيق أذونات نظام الملفات: إزالة حق الكتابة لمجلدات Program Files للمستخدمين غير الإداريين
6. تطبيق AppLocker/Windows Defender Application Control لإدراج ملفات DVR الشرعية فقط
7. تعطيل خدمة DVRWatchdog إذا لم تكن مطلوبة تشغيلياً؛ استخدم حلول مراقبة بديلة
8. عزل أنظمة DVR على شرائح شبكة منفصلة مع ضوابط صارمة للدخول والخروج
9. نشر كشف التسلل المستند إلى المضيف (HIDS) لمراقبة Program Files للتنفيذ غير المصرح به
10. فكر في الترقية إلى حلول مراقبة حديثة مع معمارية الأمان بالتصميم
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.1 - Access control policy A.6.2.1 - User registration and de-registration A.8.1.1 - Asset inventory and ownership A.12.2.1 - Change management procedures
🔵 SAMA CSF
ID.AM-1 - Asset Management PR.AC-1 - Access Control Policy PR.AC-4 - Access Rights Management DE.CM-1 - System Monitoring RS.MI-1 - Incident Response Planning
🟡 ISO 27001:2022
A.5.1.1 - Information security policies A.6.1.1 - Access control policy A.6.2.1 - User registration A.8.1.1 - Asset inventory A.12.2.1 - Change management
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-428
EPSS0.01%
Exploit No
Patch ✗ No
Published 2026-05-10
Source Feed nvd
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-428
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.