CVE-2026-25865: Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec

Published Jun 18, 2026
·
Updated

Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll ControlRunDLL input.dll. Attackers can place a malicious executable earlier in the search order to achieve arbitrary code execution in the context of the affected user.

Affected Software

1 affected component
Yandex Punto Switcher<=4.5.0.583

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Punto Switcher from your environment.

    Uninstall Punto Switcher if it is not required on affected systems to eliminate the vulnerable component.

  2. Configuration

    Modify the application so its call to WinExec supplies a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll (do not rely on the unquoted search path).

    Punto Switcher WinExec invocation = use a fully qualified path for RunDll32.exe
  3. Compensating control

    Prevent untrusted users from placing executables earlier in the search order by restricting write permissions to directories that are searched for executables (including user-writable locations and system PATH directories), and monitor systems for unexpected executables placed in those locations.

Event History

Jun 18, 2026
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-25865?

The severity of CVE-2026-25865 is high with a CVSS score of 7.8.

2

How do I fix CVE-2026-25865?

To fix CVE-2026-25865, ensure that the application paths are fully quoted in the configuration to prevent unquoted search path vulnerabilities.

3

What software is affected by CVE-2026-25865?

CVE-2026-25865 affects Yandex Punto Switcher version 4.5.0.583 and earlier.

4

What type of vulnerability is CVE-2026-25865?

CVE-2026-25865 is an unquoted search path vulnerability that allows local attackers to execute arbitrary code.

5

Can CVE-2026-25865 be exploited remotely?

No, CVE-2026-25865 can only be exploited locally by attackers with access to the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203