PT-2026-84212 · Unknown · Controlflash
CVE-2026-12663
·
Published
2026-09-01
·
Updated
2026-09-04
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ControlFLASH versions 15.07 and earlier
Description
The installer grants write permissions to the Everyone group on the product installation directory. This flaw allows for arbitrary code execution, enabling an attacker to run any commands or code of their choice on a target machine at the permission level of the logged-in user.
Recommendations
Update to version 15.08.
Fix
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Controlflash