CVE-2025-26860

7.8

RSUPPORT CO., LTD. · RemoteCall Remote Support Program (for Operator)

An uncontrolled search path element vulnerability exists in RemoteCall Remote Support Program (for Operator) before version 5.1.0, allowing arbitrary code execution via a crafted DLL.

Executive summary

The RSUPPORT RemoteCall Remote Support Program is vulnerable to arbitrary code execution through a DLL hijacking flaw, posing a significant security risk to operator workstations.

Vulnerability

The software suffers from an uncontrolled search path element (CWE-427) where an attacker can place a malicious DLL in the application directory to trigger arbitrary code execution upon execution of the program by a local user.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting a high severity due to the potential for full system compromise. Successful exploitation allows an attacker to gain the privileges of the user running the software, potentially leading to unauthorized data access, lateral movement within the network, or the installation of persistent malware on critical support infrastructure.

Remediation

Immediate Action: Upgrade the RemoteCall Remote Support Program (for Operator) to version 5.1.0 or later to resolve the search path vulnerability.

Proactive Monitoring: Monitor endpoint logs for the creation of unexpected DLL files within application directories or unusual process execution chains originating from the RemoteCall installation folder.

Compensating Controls: Restrict write permissions to the application installation directory to prevent unauthorized users from placing malicious DLL files into the search path.

Exploitation status

Public Exploit Available: No (exploit_available is false)

Analyst recommendation

This vulnerability presents a high risk to organizational security by enabling local attackers to elevate privileges via DLL hijacking. Administrators should prioritize the deployment of the vendor-supplied update to version 5.1.0 across all operator systems. If immediate patching is not feasible, ensure that non-privileged users lack write access to the directories where the RemoteCall software is installed to mitigate the threat of arbitrary code execution.

Sources