Back to CVE List

CVE-2026-3780

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.3 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-426
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!