PT-2026-26676 · Unknown · Screentogif

Kwangyun

·

Publicado

2026-03-20

·

Atualizado

2026-03-21

·

CVE-2026-33156

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ScreenToGif versions prior to 2.42.1
Description ScreenToGif is susceptible to a DLL sideloading issue via the version.dll file. When the portable executable is launched from a directory writable by the user, it loads version.dll from the application directory instead of the standard Windows System32 directory. This allows for the execution of arbitrary code within the user's context. The application is commonly distributed as a portable application, making it frequently run from user-writable locations, which increases the risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33156
GHSA-3FMJ-J696-9MG2

Produtos afetados

Screentogif