Description
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.
Published: 2026-08-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FirmaCheck for Windows versions earlier than 1.3.16 has a DLL hijacking vulnerability that permits local attackers to run arbitrary code. By placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory and referencing an attacker‑controlled DLL, the malicious library is loaded when FirmaCheck.exe starts automatically at system startup. The flaw is classified as CWE‑426 and allows code execution with the privileges of the startup process, potentially compromising the system.

Affected Systems

The affected product is Zucchetti S.p.a. FirmaCheck for Windows, versions below 1.3.16. Users of earlier builds can be impacted if the program runs automatically at system startup.

Risk and Exploitability

The CVSS score of 8.5 indicates high risk, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The attack requires local access to write an openssl.cnf file to the C:\Program Files (x86)\Common Files\SSL\ directory, after which the malicious DLL is loaded during the automatic startup of FirmaCheck.exe. Consequently, a local attacker can achieve code execution with the privileges of the started process.

Generated by OpenCVE AI on August 5, 2026 at 18:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 1.3.16 or later to eliminate the flaw.
  • Remove any openSSL configuration files from the C:\Program Files (x86)\Common Files\SSL\ directory.
  • Restrict write permissions on that directory so only trusted administrative accounts can add files.

Generated by OpenCVE AI on August 5, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup. FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zucchetti S.p.a.
Zucchetti S.p.a. firmacheck
Vendors & Products Zucchetti S.p.a.
Zucchetti S.p.a. firmacheck

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.
Title FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Zucchetti S.p.a. Firmacheck
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-05T15:58:21.552Z

Reserved: 2026-04-20T16:07:47.308Z

Link: CVE-2026-41447

cve-icon Vulnrichment

Updated: 2026-08-04T13:43:47.710Z

cve-icon NVD

Status : Received

Published: 2026-08-03T21:16:38.947

Modified: 2026-08-05T16:16:56.477

Link: CVE-2026-41447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:15:05Z

Weaknesses