DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally. | |
| Title | LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows | |
| First Time appeared |
Lucid Vision Labs
Lucid Vision Labs arena Sdk |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lucid_vision_labs:arena_sdk:1.0.80.49:*:windows:*:*:*:*:* | |
| Vendors & Products |
Lucid Vision Labs
Lucid Vision Labs arena Sdk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-08-07T15:13:36.117Z
Reserved: 2026-05-21T14:12:19.920Z
Link: CVE-2026-9169
Updated: 2026-08-07T15:13:32.289Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T11:12:49Z