Impact
An untrusted search path exists in Battery Life Diagnostic Tool software before version 2.9.0, allowing a malicious executable placed in a user‑writable directory to be selected and run under the tool’s process. Because the tool operates with ordinary user privileges, this flaw can be used by an authenticated local attacker to gain elevated rights, potentially compromising the confidentiality, integrity and availability of the system as high‑level effects are reported. The vulnerability requires local access, an authenticated user, a high‑complexity attack, and passive user interaction for exploitation.
Affected Systems
All installations of Battery Life Diagnostic Tool software with a version earlier than 2.9.0 are affected. The vendor is unspecified in the advisory, and only the major version threshold is identified.
Risk and Exploitability
The CVSS score is 5.4 and the EPSS score is less than 1%, indicating moderate base severity but a very low probability of real‑world exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access and a user with authentication, and must be performed without special internal knowledge. The exploitation path therefore runs from a local user context to a higher privilege state via the tool’s search mechanism.
OpenCVE Enrichment