Description
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 07 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally. | |
| Title | LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows | |
| First Time appeared |
Lucid Vision Labs
Lucid Vision Labs arena Sdk |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lucid_vision_labs:arena_sdk:1.0.80.49:*:windows:*:*:*:*:* | |
| Vendors & Products |
Lucid Vision Labs
Lucid Vision Labs arena Sdk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-08-07T08:47:13.136Z
Reserved: 2026-05-21T14:12:19.920Z
Link: CVE-2026-9169
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-427
Uncontrolled Search Path Element