PT-2025-20458 · Microsoft+2 · Comctl32.Dll+21
Shellkraft
·
Published
2025-05-09
·
Updated
2025-05-15
·
CVE-2025-4455
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Patch My PC Home Updater versions up to 5.1.3.0
Description
A critical issue affects some unknown processing in various system libraries, including
advapi32.dll, BCrypt.dll, comctl32.dll, crypt32.dll, dwmapi.dll, gdi32.dll, gdiplus.dll, imm32.dll, iphlpapi.dll, kernel32.dll, mscms.dll, msctf.dll, ntdll.dll, ole32.dll, oleaut32.dll, PresentationNative cor3.dll, secur32.dll, shcore.dll, shell32.dll, sspicli.dll, and System.IO. The manipulation leads to an uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high, and the exploitation is known to be difficult.Recommendations
For Patch My PC Home Updater versions up to 5.1.3.0, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
LPE
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bcrypt.Dll
Patch My Pc Home Updater
Presentationnative Cor3.Dll
System.Io
Advapi32.Dll
Comctl32.Dll
Crypt32.Dll
Dwmapi.Dll
Gdi32.Dll
Gdiplus.Dll
Imm32.Dll
Iphlpapi.Dll
Kernel32.Dll
Mscms.Dll
Msctf.Dll
Ntdll.Dll
Ole32.Dll
Oleaut32.Dll
Secur32.Dll
Shcore.Dll
Shell32.Dll
Sspicli.Dll