CVE-2025-58740: Milner Imagedirector Capture

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

Affected products

  • Milner Imagedirector Capture: from 7.0.9, before 7.6.3.25808 (fixed in 7.6.3.25808)

Published 2026-01-20. Last modified 2026-06-17.