Impact
The flaw is a classic Search Order Hijacking (CWE‑427) in ArkSigner Desktop Client. An attacker able to place a malicious executable in a directory that appears earlier in the client’s search path can cause the client to load and run that code instead of the intended binary. This can lead to arbitrary code execution and privilege escalation on the infected system.
Affected Systems
Affected is ArkSigner Desktop Client from version 2.2.16.10 through 17062026, distributed by ArkSigner Software and Hardware Industry and Trade Inc. No other vendors or products are listed.
Risk and Exploitability
With a CVSS score of 7.3 the vulnerability is considered high severity. The EPSS score is below 1%, indicating a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. Based on the description, the likely attack vector is an attacker placing a malicious binary in an earlier directory of the client’s search path and gaining influence over that path, which is typically a local or privileged action. In an environment where ArkSigner runs with elevated rights, successful exploitation could allow an attacker to execute arbitrary code with the same privileges as the client.
OpenCVE Enrichment