EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
References
Configurations
No configuration.
History
29 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Apr 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.1 |
23 Apr 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 07:16
Updated : 2026-04-29 20:16
NVD link : CVE-2025-10549
Mitre link : CVE-2025-10549
CVE.ORG link : CVE-2025-10549
JSON object : View
Products Affected
No product.
CWE
CWE-427
Uncontrolled Search Path Element
