EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
The vendor provides a patch v1.3.95 which should be installed immediately.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM. | |
| Title | DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation | |
| Weaknesses | CWE-427 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-04-23T06:57:27.220Z
Reserved: 2025-09-16T11:59:48.866Z
Link: CVE-2025-10549
No data.
Status : Received
Published: 2026-04-23T07:16:39.720
Modified: 2026-04-23T07:16:39.720
Link: CVE-2025-10549
No data.
OpenCVE Enrichment
No data.
Weaknesses