CVE-2026-25865 Details
Description
Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attackers can place a malicious executable earlier in the search order to achieve arbitrary code execution in the context of the affected user.
An unquoted search path vulnerability has been identified in Punto Switcher versions through 4.5.0.583. This vulnerability allows local attackers to execute arbitrary code by exploiting the application's unqualified call to WinExec, which lacks a full path for RunDll32.exe. When invoking shell32.dll Control_RunDLL input.dll, attackers can place a malicious executable in a directory that is searched before the System32 folder, leading to code execution in the context of the affected user.
As of now, there is no official patch available from the vendor, Yandex. However, it is recommended to audit the directories that Windows searches when Punto Switcher launches RunDll32.exe, particularly drive roots and Program Files parent directories, to ensure no unexpected executables are present. Additionally, restrict filesystem write permissions for low-privileged users on shared machines and avoid running Punto Switcher as an administrator for routine tasks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://spektion.com/articles/cve-2026-25865-punto-switcher | [email protected] | Technical Analysis |
| https://www.vulncheck.com/advisories/punto-switcher-unquoted-search-path-via-winexec | [email protected] | Advisory |
| https://yandex.ru/soft/punto | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Yandex Punto Switcher | <= 4.5.0.583 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion