CVE-2026-3000
CRITICALIDExpert 2.7.3.230719-2.8.4.250925 - Unauthenticated Remote Code Execution via Arbitrary DLL Download
Title source: llmDescription
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.
References (3)
Core 3
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10740-b2eb2-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-10741-daed4-2.html
Various Sources vendor-advisory
https://www.changingtec.com/news_detail.jsp?item_id=348
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
39.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-494
Status
published
Products (1)
changingtec/idexpert
2.7.3.230719 - 2.8.4.250925
Published
Mar 02, 2026
Tracked Since
Mar 02, 2026