CVE-2026-44406: DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44406?
CVE-2026-44406 is classified as a high-severity DLL hijacking vulnerability due to its potential for local arbitrary code execution and privilege escalation.
How do I fix CVE-2026-44406?
To mitigate CVE-2026-44406, ensure that you update ZTE uSmartView to the latest version that addresses the DLL hijacking vulnerability.
What are the risks associated with CVE-2026-44406?
The risks of CVE-2026-44406 include local arbitrary code execution, privilege escalation, and potential memory corruption on the affected systems.
Which software is affected by CVE-2026-44406?
CVE-2026-44406 affects ZTE uSmartView, specifically through the uSmartViewServiceAgent.exe component.
What causes CVE-2026-44406?
CVE-2026-44406 is caused by a DLL hijacking flaw in the ZTE uSmartView application, allowing malicious actors to manipulate DLLs loaded by the service agent.