CVE-2025-10549
MEDIUMDLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation
Title source: cnaDescription
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
Scores
CVSS v3
5.1
EPSS
0.0001
EPSS Percentile
0.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-427
Status
published
Products (1)
EfficientLab, LLC/Controlio
<1.3.95
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026