Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27532 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence. |
Thu, 29 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Updf
Updf updf |
|
| CPEs | cpe:2.3:a:updf:updf:1.8.5.0:*:*:*:*:windows:*:* | |
| Vendors & Products |
Updf
Updf updf |
|
| Metrics |
cvssV3_1
|
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows |
|
| Vendors & Products |
Microsoft
Microsoft windows |
Wed, 10 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence. | |
| Title | DLL search path hijacking vulnerability | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-10T20:22:38.145Z
Reserved: 2025-09-10T10:41:57.570Z
Link: CVE-2025-10214
Updated: 2025-09-10T20:22:33.601Z
Status : Analyzed
Published: 2025-09-10T12:15:32.690
Modified: 2026-01-29T16:07:21.720
Link: CVE-2025-10214
No data.
OpenCVE Enrichment
Updated: 2025-09-11T10:42:48Z
EUVD