OBS Studio Untrusted Search Path Vulnerability Allowing DLL Injection

Vulnerability

A vulnerability exists in OBS Studio versions up to 30.0.2 on Windows, related to how the application loads dynamic link library (DLL) files. The issue arises from an untrusted search path that can be exploited to inject malicious code into DLLs, potentially leading to remote code execution. This vulnerability requires local access to the affected system.

Impact

Exploitation of this vulnerability allows for command injection through DLL injection, with the possibility of remote code execution.

Reproduction

The vulnerability can be reproduced by placing a malicious 'profapi.dll' file in the OBS Studio installation directory. During startup, OBS Studio loads DLLs from this directory, including the injected 'profapi.dll'. If the application is configured to execute code from this DLL, the injected code will be executed, demonstrating the vulnerability.

Remediation

Users are advised to update to the patched version of OBS Studio, which is available on the OBS Project website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.