DLL search path hijacking vulnerability in the UPDF.exe...
High severity
Unreviewed
Published
Sep 10, 2025
to the GitHub Advisory Database
•
Updated Jan 20, 2026
Description
Published by the National Vulnerability Database
Sep 10, 2025
Published to the GitHub Advisory Database
Sep 10, 2025
Last updated
Jan 20, 2026
DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\Public\AppData\Local\UPDF\FREngine\Bin64' directory, which could lead to arbitrary code execution and persistence.
References