Impact
The flaw is a DLL hijacking weakness in EfficientLab Controlio versions prior to 1.3.95. Weak permissions on the installation directory allow a local user to drop a malicious DLL, which the privileged service loads, leading to execution of attacker code with the SYSTEM account. This gives full control of the machine.
Affected Systems
EfficientLab, LLC Controlio software installations running on Windows where the installation folder has insecure permissions. Versions before v1.3.95 are affected; the vendor recommends applying patch v1.3.95.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate severity risk, and the very low EPSS score of less than 1% suggests it is unlikely to be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local access to the machine and write permission to the installation directory to succeed.
OpenCVE Enrichment