CVE-2025-10549 Details
Description
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.
A DLL hijacking vulnerability has been identified in EfficientLab Controlio versions prior to 1.3.95. This vulnerability arises from weak folder permissions in the installation directory, allowing local attackers to place specially crafted DLLs that are executed with high privileges when the Controlio service is started. The service runs as NT AUTHORITY\SYSTEM, enabling attackers to execute arbitrary code with elevated rights, potentially bypassing the application's monitoring features.
Users are advised to update to EfficientLab Controlio version 1.3.95, which addresses this vulnerability. For details on how to download the update, visit the Controlio Knowledge Base.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2026CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.controlio.net/hc/en-us/articles/45777908471185-Client-Update-April-15-2026-ver-1-3-95 | SEC Consult Vulnerability Lab | Release NotesVendor |
| https://r.sec-consult.com/controlio | SEC Consult Vulnerability Lab | AdvisoryExploitRemedy |
| http://seclists.org/fulldisclosure/2026/Apr/19 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| EfficientLab Controlio | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | CVE Modified | CVE |
| Apr 23, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion