Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27531 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\Public\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence. |
Tue, 20 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Updf
Updf updf |
|
| CPEs | cpe:2.3:a:updf:updf:1.8.5.0:*:*:*:*:windows:*:* | |
| Vendors & Products |
Updf
Updf updf |
|
| Metrics |
cvssV3_1
|
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows |
|
| Vendors & Products |
Microsoft
Microsoft windows |
Wed, 10 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\Public\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence. | |
| Title | DLL search path hijacking vulnerability | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-10T20:22:06.791Z
Reserved: 2025-09-10T10:41:58.252Z
Link: CVE-2025-10215
Updated: 2025-09-10T20:22:02.039Z
Status : Analyzed
Published: 2025-09-10T12:15:32.863
Modified: 2026-01-20T20:43:36.617
Link: CVE-2025-10215
No data.
OpenCVE Enrichment
Updated: 2025-09-11T10:42:49Z
EUVD