PT-2025-47246 · Mitsubishi · Milco.S Setting Application+2
Published
2025-11-18
·
Updated
2025-11-27
·
CVE-2025-10089
CVSS v3.1
7.7
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MILCO.S Setting Application all versions
MILCO.S Setting Application (IR) all versions
MILCO.S Easy Setting Application (IR) all versions
MILCO.S Easy Switch Application (IR) all versions
Description
A security issue exists in the Setting and Operation Application for Lighting Control System MILCO.S. A local attacker can potentially execute malicious code by causing the installer to load a malicious DLL. This issue occurs during the installation process and does not affect the application after installation. Downloading and installing the product directly from the Mitsubishi Electric website mitigates the risk, as the application will be digitally signed by "Mitsubishi Electric Lighting" and therefore fixed.
Recommendations
Download and install the application directly from the Mitsubishi Electric website to ensure the application is digitally signed by "Mitsubishi Electric Lighting".
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Milco.S Easy Setting Application
Milco.S Easy Switch Application
Milco.S Setting Application