Untrusted search path vulnerability in Bandisoft Bandizip before 3.10 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory.
https://exchange.xforce.ibmcloud.com/vulnerabilities/90966
http://www.bandisoft.com/bandizip/history
http://osvdb.org/102979
Source: Mitre, NVD
Published: 2014-02-14
Updated: 2026-06-17
Base Score: 6.9
Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C
Severity: Medium
Base Score: 7.3
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00055