Dfir-Orc · Dfir-Orc · CVE-2026-11958
**Name of the Vulnerable Software and Affected Versions**
DFIR-ORC versions prior to 10.2.8
**Description**
Local privilege escalation occurs due to the loading of DLLs from a shared temporary directory. An attacker with prior system access can place a malicious DLL in 'C:WindowsTemp'. Since the application is extracted and executed from this location with administrative privileges, the malicious library can be loaded automatically, granting the attacker administrator privileges on the machine.
**Recommendations**
Update to a version later than 10.2.7.