Impact
An uncontrolled search path element flaw (CWE-427) in Fuji Electric Co., Ltd Pupsman lets an attacker place a malicious DLL next to the installer. When the installer runs, it may load the DLL and execute its code with the full rights of the SYSTEM account. It is inferred that the installer resolves DLLs from the local directory before searching system directories, but this resolution order is not explicitly stated in the description.
Affected Systems
Fuji Electric Co., Ltd Pupsman versions prior to 3.9.0 are impacted. All releases older than 3.9.0 contain the vulnerable installer.
Risk and Exploitability
The CVSS score of 8.4 signals a high severity, while the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been observed. The likely attack vector is local: an attacker who can write to the installer directory can drop a DLL file and trigger the flaw, resulting in SYSTEM‑level code execution.
OpenCVE Enrichment