Impact
FirmaCheck for Windows versions earlier than 1.3.16 has a DLL hijacking vulnerability that permits local attackers to run arbitrary code. By placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory and referencing an attacker‑controlled DLL, the malicious library is loaded when FirmaCheck.exe starts automatically at system startup. The flaw is classified as CWE‑426 and allows code execution with the privileges of the startup process, potentially compromising the system.
Affected Systems
The affected product is Zucchetti S.p.a. FirmaCheck for Windows, versions below 1.3.16. Users of earlier builds can be impacted if the program runs automatically at system startup.
Risk and Exploitability
The CVSS score of 8.5 indicates high risk, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The attack requires local access to write an openssl.cnf file to the C:\Program Files (x86)\Common Files\SSL\ directory, after which the malicious DLL is loaded during the automatic startup of FirmaCheck.exe. Consequently, a local attacker can achieve code execution with the privileges of the started process.
OpenCVE Enrichment