EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The vendor provides a patch v1.3.95 which should be installed immediately.


Workaround

No workaround given by the vendor.

History

Thu, 23 Apr 2026 07:15:00 +0000

Type Values Removed Values Added
Description EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Title DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation
Weaknesses CWE-427
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2026-04-23T06:57:27.220Z

Reserved: 2025-09-16T11:59:48.866Z

Link: CVE-2025-10549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-23T07:16:39.720

Modified: 2026-04-23T07:16:39.720

Link: CVE-2025-10549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses