CVE-2025-10089

7.0

Mitsubishi Electric · MILCO.S Setting and Operation Applications

An uncontrolled search path element vulnerability in Mitsubishi Electric MILCO.S applications allows local attackers to execute arbitrary code via malicious DLL loading during installation.

Executive summary

A vulnerability in Mitsubishi Electric MILCO.S lighting control installers allows local attackers to execute arbitrary code, posing a significant risk to system integrity.

Vulnerability

This is an uncontrolled search path element flaw (CWE-427) where the installer may load a malicious DLL if one is placed in the search path. The vulnerability requires local access and user interaction to trigger, and it is specific to the installation process rather than the post-installation runtime environment.

Business impact

Successful exploitation could allow an attacker to gain full control over the host system during the installation process, leading to complete system compromise. Given the CVSS score of 7.0, this represents a high-severity risk that could lead to unauthorized access or the installation of persistent malicious software on industrial control workstations.

Remediation

Immediate Action: Verify the integrity of the installation by checking the Digital Signatures tab of the MILCO.S Lighting Control.exe file for the signer name "Mitsubishi Electric Lighting," which indicates a patched version. If the signature is missing or incorrect, download the latest installer directly from the official Mitsubishi Electric website.

Proactive Monitoring: Monitor system logs for unexpected process execution during software installation and ensure that installers are only sourced from verified, official vendor channels.

Compensating Controls: Restrict local user privileges on engineering workstations to prevent unauthorized file placement in directories where the installer searches for dependencies.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk posed by this vulnerability is significant for environments utilizing MILCO.S lighting control systems. Administrators must ensure that all future installations of this software are performed using validated, digitally signed files obtained exclusively from Mitsubishi Electric to mitigate the risk of malicious DLL injection.

More Mitsubishi Electric CVEs

Sources