CVE-2026-11958

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-18 14:17

Updated : 2026-06-22 19:45


NVD link : CVE-2026-11958

Mitre link : CVE-2026-11958

CVE.ORG link : CVE-2026-11958


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element