Impact
The installer of HYPER SBI 2 loads dynamic link libraries from the current directory without verifying the source of those DLLs. If a malicious DLL is present in the same folder when the installer is executed, it will be loaded and its code will run with the privileges of the user performing the installation. This flaw allows local execution of attacker‑supplied code during the setup process.
Affected Systems
The vendor SBI SECURITIES Co.,Ltd. issues the HYPER SBI 2 installer. Any installation that uses the vulnerable installer is affected. The advisory does not disclose specific version ranges, so all builds that include the current installation routine are potentially impacted.
Risk and Exploitability
The CVSS score of 8.4 classifies this as high severity. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires the attacker to place a crafted DLL in the directory holding the installer and then have the user run the setup, thus the attack vector is local. The impact is limited to the privileges of the account that launches the installation.
OpenCVE Enrichment