Back to overview

CVE-2019-25268

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and libegl.dll by placing malicious libraries on WebDAV or SMB shares to execute unauthorized code.

Metadata

CVE ID
CVE-2019-25268
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-01-06 16:07 UTC
Published
2026-01-07 23:09 UTC
Last updated
2026-01-08 19:26 UTC
Primary CWE
CWE-427
Uncontrolled Search Path Element
Vendor / Product
NREL / BEopt
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
NREL BEopt 2.8.0.0, 2.7.0.0, 2.6.0.1
Weakness (CWE)
CWESourceDescription
CWE-427 cna Uncontrolled Search Path Element
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
8.6 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (5)
Back to overview