CVE-2026-44612 PUBLISHED

Assigner: jpcert
Reserved: 07.05.2026 Published: 13.05.2026 Updated: 13.05.2026

Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Bytello
Product Bytello Share (Windows Edition) installer executable
Versions
  • Version prior to 5.13.0.4246 is affected

References

Problem Types