PT-2026-50662 · Dfir-Orc · Dfir-Orc
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
DFIR-ORC versions prior to 10.2.8
Description
Local privilege escalation occurs due to the loading of DLLs from a shared temporary directory. An attacker with prior system access can place a malicious DLL in 'C:WindowsTemp'. Since the application is extracted and executed from this location with administrative privileges, the malicious library can be loaded automatically, granting the attacker administrator privileges on the machine.
Recommendations
Update to a version later than 10.2.7.
Exploit
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dfir-Orc