PT-2026-3843 · D Link · D-Link D-View 8

·

CVE-2026-23755

·

Publicado

2026-01-21

·

Atualizado

2026-01-21

CVSS v4.0

8.4

Alta

VetorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions D-Link D-View 8 versions 2.0.1.107 and below
Description D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via User Account Control (UAC), the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer. When a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges, potentially leading to full system compromise.
Recommendations Versions prior to 2.0.1.107 should be updated.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00980
CVE-2026-23755

Produtos afetados

D-Link D-View 8