PT-2026-31468 · Ufrisk+1 · Memprocfs
CVE-2026-40031
·
Published
2026-04-08
·
Updated
2026-04-08
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MemProcFS versions prior to 5.17
Description
Unsafe library-loading patterns across six attack surfaces allow for DLL and shared-library hijacking. This occurs due to the use of bare-name
LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An attacker can achieve arbitrary code execution by placing a malicious library in the working directory or by manipulating the LD LIBRARY PATH environment variable.Recommendations
Update MemProcFS to version 5.17 or later.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Memprocfs