PT-2026-1673 · Sdl2.Dll+2 · Sdl2.Dll+2
CVE-2019-25268
·
Publicado
2026-01-07
·
Atualizado
2026-01-08
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NREL BEopt version 2.8.0.0
Description
The software contains a DLL hijacking issue that enables attackers to load arbitrary libraries. This is achieved by deceiving users into opening application files from remote shares. The insecure loading of
sdl2.dll and libegl.dll allows attackers to place malicious libraries on WebDAV or SMB shares, leading to the execution of unauthorized code.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Beopt
Libegl.Dll
Sdl2.Dll