Crucial Storage Executive DLL Preloading Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A DLL preloading vulnerability has been identified in the Crucial Storage Executive installer, affecting versions prior to 11.08.082025.00. The vulnerability arises because the installer, which runs with elevated privileges, loads Windows DLLs using an uncontrolled search path. This flaw can be exploited by placing a malicious DLL in the same directory as the installer, leading to arbitrary code execution with administrator privileges. The issue requires local access to the victim's machine.

Impact

Exploitation of this vulnerability allows for arbitrary code execution with administrator privileges.

Added: Jan 26, 2026, 6:34 PM
Updated: Jan 26, 2026, 6:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.