Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27533 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxtn.dll file of their choice in the 'C:\Users\<user>\AppData\Local\Microsoft\WindowsApps\' directory, which could lead to arbitrary code execution and persistence. |
Thu, 29 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Updf
Updf updf |
|
| CPEs | cpe:2.3:a:updf:updf:1.8.5.0:*:*:*:*:windows:*:* | |
| Vendors & Products |
Updf
Updf updf |
|
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows |
|
| Vendors & Products |
Microsoft
Microsoft windows |
Wed, 10 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxtn.dll file of their choice in the 'C:\Users\<user>\AppData\Local\Microsoft\WindowsApps\' directory, which could lead to arbitrary code execution and persistence. | |
| Title | DLL search path hijacking vulnerability | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-10T20:23:13.325Z
Reserved: 2025-09-10T10:41:56.630Z
Link: CVE-2025-10213
Updated: 2025-09-10T20:23:09.683Z
Status : Analyzed
Published: 2025-09-10T12:15:31.250
Modified: 2026-01-29T01:50:08.670
Link: CVE-2025-10213
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:28Z
EUVD