Unrated severityNVD Advisory· Published Jun 18, 2026
Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
CVE-2026-25865
Description
Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attackers can place a malicious executable earlier in the search order to achieve arbitrary code execution in the context of the affected user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.5.0.583
Patches
Vulnerability mechanics
References
3- spektion.com/articles/cve-2026-25865-punto-switchermitrevendor-advisory
- www.vulncheck.com/advisories/punto-switcher-unquoted-search-path-via-winexecmitrethird-party-advisory
- yandex.ru/soft/puntomitreproduct
News mentions
0No linked articles in our index yet.