CVE-2026-11958 Details
Description
Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.
A local privilege escalation vulnerability has been identified in ANSSI's DFIR-ORC tool, affecting versions through 10.2.7. The issue arises from the application loading dynamic link libraries (DLLs) from a shared temporary directory. An attacker with access to the system can place a malicious DLL in the Windows Temp directory and wait for DFIR-ORC to be executed. Since the application runs with administrative privileges, the malicious DLL can be loaded automatically, granting the attacker elevated rights on the machine.
Users can upgrade to DFIR-ORC version 10.2.8 or later, where this vulnerability has been addressed. For those using version 10.2.7 or prior, it is recommended not to execute the application from a directory with overly permissive permissions, and to avoid running it as the System user unless the temporary directory is set to a location with appropriate permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DFIR-ORC/dfir-orc/releases/tag/v10.3.0 | [email protected] | Release NotesVendor |
| https://www.incibe.es/en/incibe-cert/notices/aviso/local-privilege-escalation-anssis-dfir-orc | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ANSSI DFIR-ORC | <= 10.2.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | New CVE Received | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
Volerion