CVE-2026-21408

7.3

FUJIFILM Business Innovation Corp. · beat-access for Windows

A DLL search path vulnerability in FUJIFILM beat-access for Windows allows local attackers to execute arbitrary code with SYSTEM privileges.

Executive summary

A high-severity DLL hijacking vulnerability in FUJIFILM beat-access for Windows allows local users to escalate privileges to SYSTEM.

Vulnerability

This is a DLL hijacking flaw (CWE-427) where the application insecurely loads dynamic link libraries due to an uncontrolled search path. A locally authenticated user with low privileges can trigger the execution of malicious code with SYSTEM-level permissions.

Business impact

Successful exploitation grants an attacker full control over the affected system, leading to potential data theft, malware deployment, or complete system compromise. Given the CVSS score of 7.3, this vulnerability represents a significant risk to organizational endpoints, particularly in environments where local user access is provided to potentially untrusted individuals.

Remediation

Immediate Action: Update the beat-access for Windows client to a version later than 3.0.3 as specified in the official FUJIFILM security announcement.

Proactive Monitoring: Review endpoint logs for unexpected file creation or modification events within the application installation directory, specifically looking for unauthorized DLL files.

Compensating Controls: Implement strict file system permissions on application directories to prevent non-privileged users from writing or modifying files where the application performs library lookups.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability poses a severe risk to host integrity by allowing privilege escalation from a standard user account. Administrators should prioritize the deployment of the vendor-supplied patch across all workstations running the affected version of the beat-access software to eliminate the risk of arbitrary code execution.

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written

Sources