CVE-2025-10549

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Configurations

No configuration.

History

29 Apr 2026, 20:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2026/Apr/19 -

23 Apr 2026, 15:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1

23 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 07:16

Updated : 2026-04-29 20:16


NVD link : CVE-2025-10549

Mitre link : CVE-2025-10549

CVE.ORG link : CVE-2025-10549


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element