CVE-2025-66835: TrueConf

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.

Affected products

Published 2025-12-30. Last modified 2026-07-05.