HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11958Published Modified CNA INCIBE

CVE-2026-11958: Local privilege escalation in ANSSI’s DFIR-ORC

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.

Metrics

CVSS v4.0
7.3
Severity
HIGH
Fixed in
10.3.0
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

Fix available

10.3.0
Patch commits
Affected packages
  • ANSSI / DFIR-ORC
    ≤ 10.2.7
    Fixed in 10.3.0
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H