PT-2026-50662 · Dfir-Orc · Dfir-Orc

·

CVE-2026-11958

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DFIR-ORC versions prior to 10.2.8
Description Local privilege escalation occurs due to the loading of DLLs from a shared temporary directory. An attacker with prior system access can place a malicious DLL in 'C:WindowsTemp'. Since the application is extracted and executed from this location with administrative privileges, the malicious library can be loaded automatically, granting the attacker administrator privileges on the machine.
Recommendations Update to a version later than 10.2.7.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11958

Affected Products

Dfir-Orc