PT-2026-1673 · Sdl2.Dll+2 · Sdl2.Dll+2
Published
2026-01-07
·
Updated
2026-01-08
·
CVE-2019-25268
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NREL BEopt version 2.8.0.0
Description
The software contains a DLL hijacking issue that enables attackers to load arbitrary libraries. This is achieved by deceiving users into opening application files from remote shares. The insecure loading of
sdl2.dll and libegl.dll allows attackers to place malicious libraries on WebDAV or SMB shares, leading to the execution of unauthorized code.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beopt
Libegl.Dll
Sdl2.Dll