Impact
An authenticated local user can place a malicious DLL in the directory where the eAI Technologies ERP F2 application resides, causing the program to load the crafted library and execute arbitrary code. The vulnerability is a classic DLL hijacking flaw, allowing the attacker to gain the same privileges as the running process.
Affected Systems
The flaw has been identified in eAI Technologies' ERP F2 product. The vendor’s fix is released in ERP F10 (the PowerBuilder 2025 version). No other products or versions are currently listed as affected.
Risk and Exploitability
The CVSS score of 8.5 classifies the vulnerability as High severity, reflecting the significant impact of arbitrary code execution on confidentiality, integrity, and availability. The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is inferred to be local authenticated access, as the description specifies that an authenticated, local attacker can place a crafted DLL in the program directory.
OpenCVE Enrichment