PT-2026-1673 · Sdl2.Dll+2 · Sdl2.Dll+2

Published

2026-01-07

·

Updated

2026-01-08

·

CVE-2019-25268

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NREL BEopt version 2.8.0.0
Description The software contains a DLL hijacking issue that enables attackers to load arbitrary libraries. This is achieved by deceiving users into opening application files from remote shares. The insecure loading of sdl2.dll and libegl.dll allows attackers to place malicious libraries on WebDAV or SMB shares, leading to the execution of unauthorized code.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2019-25268

Affected Products

Beopt
Libegl.Dll
Sdl2.Dll