High severity7.8NVD Advisory· Published Jun 18, 2026· Updated Jun 23, 2026
CVE-2026-25865
CVE-2026-25865
Description
Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attackers can place a malicious executable earlier in the search order to achieve arbitrary code execution in the context of the affected user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.5.0.583
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.