PT-2026-26676 · Unknown · Screentogif
Kwangyun
·
Published
2026-03-20
·
Updated
2026-03-21
·
CVE-2026-33156
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ScreenToGif versions prior to 2.42.1
Description
ScreenToGif is susceptible to a DLL sideloading issue via the
version.dll file. When the portable executable is launched from a directory writable by the user, it loads version.dll from the application directory instead of the standard Windows System32 directory. This allows for the execution of arbitrary code within the user's context. The application is commonly distributed as a portable application, making it frequently run from user-writable locations, which increases the risk.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Uncontrolled Search Path Element
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Screentogif