CVE-2026-25191

HIGH

FinalCode Client - DLL Hijacking

Title source: llm
STIX 2.1

Description

The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
Digital Arts Inc./FinalCode Ver.5 series prior to 5.43R01
Digital Arts Inc./FinalCode Ver.6 series prior to 6.51R01
Published Feb 26, 2026
Tracked Since Feb 26, 2026