Description
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.
References
Product
https://github.com/x00nullbit/CVE-References/blob/main/CVE-2025-66835/README.md
ExploitThird Party Advisory
https://github.com/x00nullbit/CVE-References/blob/main/CVE-2025-66835/README.md
ExploitThird Party Advisory
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-427
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
7.1 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-12-30T19:15:44.843Z
2 weeks agoLast modified
2026-01-09T19:40:20.430Z
1 week ago