CVE-2026-34488

7.3

i-PRO Co., Ltd. · IP Setting Software

i-PRO IP Setting Software is susceptible to a DLL hijacking vulnerability due to an uncontrolled search path, which could allow for arbitrary code execution with administrative privileges.

Executive summary

A DLL search path vulnerability in i-PRO IP Setting Software enables local attackers to achieve arbitrary code execution with administrative privileges.

Vulnerability

This vulnerability is a DLL hijacking flaw caused by an uncontrolled search path (CWE-427). A local attacker with low privileges can force the application to load malicious libraries, resulting in arbitrary code execution with administrative rights.

Business impact

The ability for a local user to escalate privileges to administrator status poses a significant threat to system integrity and data confidentiality. Given the CVSS score of 7.3, this high-severity flaw could allow an attacker to gain full control over affected workstations, facilitating lateral movement or the deployment of further malicious payloads within the network.

Remediation

Immediate Action: Update i-PRO IP Setting Software to version V5.20 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system logs for unauthorized file access or the execution of unexpected binaries within the application directory.

Compensating Controls: Restrict write permissions on application directories and folders where DLLs are loaded to prevent unauthorized modification by low-privileged users.

Exploitation status

Public Exploit Available: exploit_available (false).

Analyst recommendation

This vulnerability presents a clear path to privilege escalation for local attackers. System administrators should prioritize updating the i-PRO IP Setting Software to V5.20 immediately to eliminate the insecure DLL loading behavior and secure the host environment.

Sources