CVE-2025-10549

MEDIUM

DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation

Title source: cna
STIX 2.1

Description

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.

Scores

CVSS v3 5.1
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
EfficientLab, LLC/Controlio <1.3.95
Published Apr 23, 2026
Tracked Since Apr 23, 2026