Impact
AVACAST, a product of eMPIA Technology, contains a DLL hijacking vulnerability (CWE-427) that permits authenticated local users to place a malicious DLL in a designated directory. When the system subsequently loads the DLL, the malicious code runs with system privileges, allowing complete compromise of the affected machine and its resources.
Affected Systems
The vulnerability affects eMPIA Technology's AVACAST product. No specific version information is provided in the CNA data, so all versions prior to the published fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity. EPSS data is unavailable, and the issue is not listed in CISA's KEV catalog, but the risk remains significant for environments where local users have write access to the DLL directory. Exploitation requires local authenticated access and the ability to place a DLL; once the DLL is loaded, the attacker gains system-level privileges. Therefore, systems with AVACAST should treat this as a high‑priority vulnerability until patched.
OpenCVE Enrichment