PT-2025-17582 · Unknown · Dpmadirektpro

Manjyot Singh

·

Published

2025-04-22

·

Updated

2025-04-24

·

CVE-2025-43950

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DPMAdirektPro version 4.1.5
Description The issue allows for DLL Hijacking by placing a malicious DLL in a directory, which is then loaded by the application instead of the legitimate DLL. This results in the malicious DLL loading with the same privileges as the application, causing a privilege escalation.
Recommendations For DPMAdirektPro version 4.1.5, consider restricting access to directories where the application loads DLLs to prevent malicious DLLs from being loaded. As a temporary workaround, ensure that all required legitimate DLLs are present in the expected directories to minimize the risk of exploitation.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2025-43950

Affected Products

Dpmadirektpro