VYPR
High severity7.2NVD Advisory· Published Mar 18, 2016· Updated May 6, 2026

CVE-2016-2281

CVE-2016-2281

Description

DLL hijacking vulnerability in ABB Panel Builder 800 5.1 allows local attackers to execute arbitrary code via a malicious DLL in the working directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DLL hijacking vulnerability in ABB Panel Builder 800 5.1 allows local attackers to execute arbitrary code via a malicious DLL in the working directory.

Vulnerability

ABB Panel Builder 800 version 5.1 contains an uncontrolled search path element vulnerability (CWE-427). The application loads DLLs without specifying an absolute path, causing Windows to search the current working directory first. If an attacker places a malicious DLL in that directory, it will be loaded instead of the legitimate system DLL. Version 6.0 is not affected [1].

Exploitation

An attacker must have local access to the system and the ability to write a malicious DLL into the current working directory from which Panel Builder 800 is launched. When a user starts the application from that directory, the malicious DLL is loaded automatically. No additional user interaction is required beyond launching the application [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the user running Panel Builder 800. This can lead to full system compromise, including data exfiltration, modification, or installation of persistent malware [1].

Mitigation

ABB has released Panel Builder 800 version 6.0, which is not affected by this vulnerability. Users should upgrade to version 6.0 or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the advisory date [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:abb:panel_builder_800:5.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:abb:panel_builder_800:5.1:*:*:*:*:*:*:*
    • (no CPE)range: =5.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.