PT-2025-54213 · Trueconf · Trueconf Client

X00Nullbit

·

Published

2025-12-30

·

Updated

2026-01-02

·

CVE-2025-66835

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TrueConf Client version 8.5.2
Description The software is susceptible to a DLL hijacking issue. A crafted wfapi.dll file can be used by a local attacker to execute arbitrary code with the privileges of the user. The attack involves exploiting a weakness in how the application loads dynamic link libraries.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, ensure the application directory and its subdirectories have restricted permissions to prevent unauthorized modification of DLL files.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04787
CVE-2025-66835

Affected Products

Trueconf Client