CVE-2026-25191

7.8

Digital Arts Inc. · FinalCode Client

The FinalCode Client installer contains an uncontrolled DLL search path vulnerability that allows local attackers to execute arbitrary code with the privileges of the installer.

Executive summary

A DLL hijacking vulnerability in the FinalCode Client installer permits local attackers to execute arbitrary code with elevated privileges if a malicious DLL is placed in the same directory.

Vulnerability

The vulnerability is an uncontrolled search path element (CWE-427) within the software installer. An unauthenticated attacker can achieve arbitrary code execution by convincing a user to place a malicious DLL in the same directory as the installer and execute it.

Business impact

The exploitation of this vulnerability allows for full compromise of the local system with the privileges of the installer process. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized system access, data theft, or the installation of persistent malware.

Remediation

Immediate Action: Update the FinalCode Client to version 5.43R01 or 6.51R01 or later as provided by Digital Arts Inc.

Proactive Monitoring: Monitor system logs for unexpected file creation activities in directories where installers are typically executed or stored.

Compensating Controls: Ensure that users do not run installers from untrusted or shared directories where malicious files could be pre-placed by other local users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a significant risk to local system integrity. Administrators should prioritize the deployment of the patched versions released by Digital Arts Inc. to eliminate the DLL search path weakness. Until patches are applied, restrict user access to directories where software installers are staged to prevent the placement of malicious payloads.

More Digital Arts Inc. CVEs

Sources