CVE-2018-0649
Description
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The installers of multiple Canon IT Solutions security products are vulnerable to an untrusted search path attack, allowing arbitrary code execution via a malicious DLL.
Vulnerability
The installers of multiple Canon IT Solutions Inc. security products — including ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones) — contain an untrusted search path vulnerability (CWE-427) due to an insecure DLL search path [1]. All installer versions with digital timestamps before July 10, 2018 are affected [1].
Exploitation
An attacker must place a specially crafted Trojan horse DLL in an unspecified directory where the installer is executed, such as the same directory as the installer file or the Windows search path [1]. The user must then run the installer with normal user privileges, which triggers the insecure DLL loading sequence [1].
Impact
If the lure DLL is loaded, arbitrary code execution occurs with the privileges of the user invoking the installer [1]. This can lead to full compromise of the affected user’s system, including disclosure, modification, or destruction of data, and installation of further malware [1].
Mitigation
Canon IT Solutions Inc. has provided updated installers with digital timestamps on or after July 10, 2018 that fix the issue [1]. Users should download and use the latest installer from the vendor's official site. As a workaround, users should verify that no suspicious files exist in the directory where the installer resides before executing it [1]. The vulnerability affects only the installer itself; already-installed programs are not at risk [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Canon IT Solutions Inc./The installers of multiple Canon IT Solutions Inc. software programsv5Range: (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones))
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN41452671/index.htmlmitrethird-party-advisoryx_refsource_JVN
- eset-support.canon-its.jp/faq/show/10720mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.