EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM. | |
| Title | DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation | |
| Weaknesses | CWE-427 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-04-23T06:57:27.220Z
Reserved: 2025-09-16T11:59:48.866Z
Link: CVE-2025-10549
No data.
Status : Received
Published: 2026-04-23T07:16:39.720
Modified: 2026-04-23T07:16:39.720
Link: CVE-2025-10549
No data.
OpenCVE Enrichment
No data.