EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Efficientlab
Efficientlab controlio |
|
| Vendors & Products |
Efficientlab
Efficientlab controlio |
Thu, 23 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 23 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM. | |
| Title | DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation | |
| Weaknesses | CWE-427 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2026-04-23T06:57:27.220Z
Updated: 2026-04-29T19:32:11.851Z
Reserved: 2025-09-16T11:59:48.866Z
Link: CVE-2025-10549
Updated: 2026-04-29T19:32:11.851Z
Status : Awaiting Analysis
Published: 2026-04-23T07:16:39.720
Modified: 2026-04-29T20:16:28.170
Link: CVE-2025-10549
No data.
ReportizFlow