← All Advisories

CVE-2026-41447

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-41447

Key Details

CVECVE-2026-41447
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsZucchetti S.p.a. FirmaCheck
Classified asCWE-426 (Untrusted Search Path)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Zucchetti S.p.a.FirmaCheck
SubsystemsGeneral OT
SectorsMultiple

What to Know

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup. (NVD)

What to Do

Monitor Zucchetti S.p.a.'s web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41447
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-41447