CVE-2026-41447: FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path
FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege level when FirmaCheck.exe runs automatically at system startup.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FirmaCheck for Windowsto a version that resolves this vulnerability.Fixed in 1.3.16 - Compensating control
Ensure the C:\Program Files (x86)\Common Files\SSL\ directory is not writable by untrusted/local attackers so a crafted openssl.cnf cannot be placed there (mitigate DLL hijacking via unvalidated OpenSSL configuration path)
- Operational
Check for and remove any attacker-planted openssl.cnf files in C:\Program Files (x86)\Common Files\SSL\ that could be used by FirmaCheck.exe at startup
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41447?
CVE-2026-41447 has a high severity rating of 7.8.
How do I fix CVE-2026-41447?
To fix CVE-2026-41447, upgrade to FirmaCheck version 1.3.16 or later, which resolves the DLL hijacking vulnerability.
What type of vulnerability is CVE-2026-41447?
CVE-2026-41447 is a DLL hijacking vulnerability that allows local attackers to execute arbitrary code.
What impact does CVE-2026-41447 have on my system?
CVE-2026-41447 can lead to arbitrary code execution on affected systems, compromising their integrity and availability.
Can CVE-2026-41447 be exploited remotely?
No, CVE-2026-41447 requires local access to the system to be exploited.