A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
sophos hitmanpro.alert