PT-2025-54213 · Trueconf · Trueconf Client
X00Nullbit
·
Published
2025-12-30
·
Updated
2026-01-02
·
CVE-2025-66835
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TrueConf Client version 8.5.2
Description
The software is susceptible to a DLL hijacking issue. A crafted
wfapi.dll file can be used by a local attacker to execute arbitrary code with the privileges of the user. The attack involves exploiting a weakness in how the application loads dynamic link libraries.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, ensure the application directory and its subdirectories have restricted permissions to prevent unauthorized modification of DLL files.
Exploit
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trueconf Client