PT-2025-47246 · Mitsubishi · Milco.S Setting Application+2

Published

2025-11-18

·

Updated

2025-11-27

·

CVE-2025-10089

CVSS v3.1

7.7

High

VectorAV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MILCO.S Setting Application all versions MILCO.S Setting Application (IR) all versions MILCO.S Easy Setting Application (IR) all versions MILCO.S Easy Switch Application (IR) all versions
Description A security issue exists in the Setting and Operation Application for Lighting Control System MILCO.S. A local attacker can potentially execute malicious code by causing the installer to load a malicious DLL. This issue occurs during the installation process and does not affect the application after installation. Downloading and installing the product directly from the Mitsubishi Electric website mitigates the risk, as the application will be digitally signed by "Mitsubishi Electric Lighting" and therefore fixed.
Recommendations Download and install the application directly from the Mitsubishi Electric website to ensure the application is digitally signed by "Mitsubishi Electric Lighting".

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2025-10089

Affected Products

Milco.S Easy Setting Application
Milco.S Easy Switch Application
Milco.S Setting Application