PT-2025-20458 · Microsoft+2 · Comctl32.Dll+21

Shellkraft

·

Published

2025-05-09

·

Updated

2025-05-15

·

CVE-2025-4455

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Patch My PC Home Updater versions up to 5.1.3.0
Description A critical issue affects some unknown processing in various system libraries, including advapi32.dll, BCrypt.dll, comctl32.dll, crypt32.dll, dwmapi.dll, gdi32.dll, gdiplus.dll, imm32.dll, iphlpapi.dll, kernel32.dll, mscms.dll, msctf.dll, ntdll.dll, ole32.dll, oleaut32.dll, PresentationNative cor3.dll, secur32.dll, shcore.dll, shell32.dll, sspicli.dll, and System.IO. The manipulation leads to an uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high, and the exploitation is known to be difficult.
Recommendations For Patch My PC Home Updater versions up to 5.1.3.0, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

LPE

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2025-4455

Affected Products

Bcrypt.Dll
Patch My Pc Home Updater
Presentationnative Cor3.Dll
System.Io
Advapi32.Dll
Comctl32.Dll
Crypt32.Dll
Dwmapi.Dll
Gdi32.Dll
Gdiplus.Dll
Imm32.Dll
Iphlpapi.Dll
Kernel32.Dll
Mscms.Dll
Msctf.Dll
Ntdll.Dll
Ole32.Dll
Oleaut32.Dll
Secur32.Dll
Shcore.Dll
Shell32.Dll
Sspicli.Dll