Impact
The vulnerability is an uncontrolled search path element flaw (CWE‑427) present in Fuji Electric Co., Ltd. Pupsman installer binaries before version 3.9.0. If a malicious DLL is placed in the same directory as the installer and the installer runs, it may resolve that DLL before searching secure system folders and load the attacker’s code. The code would then execute with the full rights of the SYSTEM account, giving the attacker unfettered control over the target machine.
Affected Systems
Fuji Electric Co., Ltd. Pupsman versions earlier than 3.9.0 are affected. The vulnerability exists in all releases that include the vulnerable installer, which is typically distributed with the UPS software.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, but the EPSS score of less than 1% implies the likelihood of public exploitation is currently low. The vulnerability is not listed in CISA KEV, so no widespread exploitation has been documented. The attack vector is local; an attacker who can write to the installer directory and trigger the installation process can obtain SYSTEM privilege. If the affected software is running with that privilege or the installer is executed by an administrator, the attacker gains full control.
OpenCVE Enrichment