ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.
References
| Link | Resource |
|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/8107253322107965601 | Vendor Advisory |
Configurations
History
08 May 2026, 16:59
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:* | |
| References | () https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/8107253322107965601 - Vendor Advisory | |
| First Time |
Zte zxcloud Irai
Zte |
07 May 2026, 14:56
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 08:16
Updated : 2026-05-08 16:59
NVD link : CVE-2026-44406
Mitre link : CVE-2026-44406
CVE.ORG link : CVE-2026-44406
JSON object : View
Products Affected
zte
- zxcloud_irai
CWE
CWE-427
Uncontrolled Search Path Element
