{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/firmacheck/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-41447"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FirmaCheck"],"_cs_severities":["high"],"_cs_tags":["vulnerability","dll-hijacking","local-privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Zucchetti"],"content_html":"\u003cp\u003eFirmaCheck for Windows, a document signing utility by Zucchetti, contains a DLL hijacking vulnerability (CVE-2026-41447) affecting all versions prior to 1.3.16. The vulnerability stems from the application's failure to properly validate the directory path when loading the OpenSSL configuration file (openssl.cnf). An attacker with local access to the system can place a maliciously crafted openssl.cnf file into the C:\\Program Files (x86)\\Common Files\\SSL\\ directory. When the FirmaCheck.exe process initializes, it inadvertently loads a DLL specified within the attacker-controlled configuration file. Because FirmaCheck.exe is configured to execute automatically upon system startup, this flaw allows a local attacker to achieve arbitrary code execution with the privileges of the startup process, facilitating persistence and privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains local access to the target Windows system.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the path C:\\Program Files (x86)\\Common Files\\SSL\\ as a writable location or utilizes elevated privileges to create the directory structure if it does not exist.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious openssl.cnf file configured to load an attacker-supplied DLL.\u003c/li\u003e\n\u003cli\u003eAttacker places the malicious openssl.cnf file into the target directory.\u003c/li\u003e\n\u003cli\u003eAttacker places the payload DLL on the system in a location referenced by the crafted configuration file.\u003c/li\u003e\n\u003cli\u003eThe target system reboots or the user logs in, triggering the automatic execution of FirmaCheck.exe.\u003c/li\u003e\n\u003cli\u003eFirmaCheck.exe reads the malicious openssl.cnf file during its initialization sequence.\u003c/li\u003e\n\u003cli\u003eFirmaCheck.exe executes the malicious DLL, granting the attacker code execution at the process privilege level.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to execute arbitrary code on the affected Windows host. This facilitates persistence, potential privilege escalation, and full compromise of the local machine. The vulnerability affects all users of FirmaCheck prior to version 1.3.16, primarily impacting organizations using this software for document management and digital signatures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FirmaCheck to version 1.3.16 or later immediately to patch CVE-2026-41447.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided in this brief to monitor for unauthorized creation of openssl.cnf files in standard paths.\u003c/li\u003e\n\u003cli\u003eAudit the C:\\Program Files (x86)\\Common Files\\SSL\\ directory for suspicious configuration files or unexpected DLL files if patching cannot be performed immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T22:49:10Z","date_published":"2026-08-03T22:49:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-firmacheck-dll-hijacking/","summary":"FirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.","title":"DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration","url":"https://feed.craftedsignal.io/briefs/2026-08-firmacheck-dll-hijacking/"}],"language":"en","title":"CraftedSignal Threat Feed - FirmaCheck","version":"https://jsonfeed.org/version/1.1"}