CVE-2025-66835: TrueConf
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.
Affected products
- TrueConf TrueConf: version 8.5.2 only
Published 2025-12-30. Last modified 2026-07-05.