Impact
The vulnerability allows a local attacker who can place a crafted file on the system to trigger execution of arbitrary code by exploiting insecure file permissions. Because the attacker can control the file’s content and the system will execute it, they can gain unauthorized control over the affected application and potentially the underlying OS. The impact is full compromise of the compromised host’s confidentiality, integrity, and availability.
Affected Systems
The affected product is DeepCool DeepCreative, versions 1.2.7 and earlier. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score is not available. Although it is not listed in CISA's KEV catalog, this local code execution vulnerability is a very high‑risk condition. If the attacker can write files into a directory monitored by DeepCreative, they can execute arbitrary code without additional authentication. The exploitation likelihood is high for systems where the application runs with elevated privileges or unsegmented file permissions, and administrators should assume the risk remains elevated until a vendor update is applied.
OpenCVE Enrichment