CVE-2025-10549: Efficientlab, Llc Controlio

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM.

Affected products

Published 2026-04-23. Last modified 2026-10-07.