PT-2026-1673 · Sdl2.Dll+2 · Sdl2.Dll+2

CVE-2019-25268

·

Publicado

2026-01-07

·

Atualizado

2026-01-08

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NREL BEopt version 2.8.0.0
Description The software contains a DLL hijacking issue that enables attackers to load arbitrary libraries. This is achieved by deceiving users into opening application files from remote shares. The insecure loading of sdl2.dll and libegl.dll allows attackers to place malicious libraries on WebDAV or SMB shares, leading to the execution of unauthorized code.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25268

Produtos afetados

Beopt
Libegl.Dll
Sdl2.Dll