DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 10 Sep 2025 11:45:00 +0000

Type Values Removed Values Added
Description DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence.
Title DLL search path hijacking vulnerability
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-09-10T11:39:12.641Z

Reserved: 2025-09-10T10:41:57.570Z

Link: CVE-2025-10214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-10T12:15:32.690

Modified: 2025-09-10T12:15:32.690

Link: CVE-2025-10214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.