CVE-2025-10549 PUBLISHED

DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation

Assigner: SEC-VLab
Reserved: 16.09.2025 Published: 23.04.2026 Updated: 23.04.2026

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.

Product Status

Vendor EfficientLab, LLC
Product Controlio
Versions Default: unaffected
  • Version <1.3.95 is affected

Solutions

The vendor provides a patch v1.3.95 which should be installed immediately.

Credits

  • Tobias Niemann, SEC Consult Vulnerability Lab finder
  • Daniel Hirschberger, SEC Consult Vulnerability Lab finder
  • Thorger Jansen, SEC Consult Vulnerability Lab finder
  • Marius Renner, SEC Consult Vulnerability Lab finder

References

Problem Types

  • CWE-427 Uncontrolled Search Path Element CWE

Impacts

  • CAPEC-471 Search Order Hijacking