PT-2026-26676 · Unknown · Screentogif
Kwangyun
·
Publicado
2026-03-20
·
Atualizado
2026-03-21
·
CVE-2026-33156
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ScreenToGif versions prior to 2.42.1
Description
ScreenToGif is susceptible to a DLL sideloading issue via the
version.dll file. When the portable executable is launched from a directory writable by the user, it loads version.dll from the application directory instead of the standard Windows System32 directory. This allows for the execution of arbitrary code within the user's context. The application is commonly distributed as a portable application, making it frequently run from user-writable locations, which increases the risk.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Search Path Element
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Screentogif