DLL search path hijacking vulnerability in the UPDF.exe...
High severity
Unreviewed
Published
Sep 10, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Sep 10, 2025
Published to the GitHub Advisory Database
Sep 10, 2025
DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxtn.dll file of their choice in the 'C:\Users<user>\AppData\Local\Microsoft\WindowsApps' directory, which could lead to arbitrary code execution and persistence.
References