CVE-2025-30248
DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.58%
- CWE
- CWE-427
- Published
- 2026-01-26
- Last modified
- 2026-03-12
Affected products
- Western Digital WD Discovery
Weakness type
Related vulnerabilities
- CVE-2019-25268 — NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution
- CVE-2025-65118 — AVEVA Process Optimization Uncontrolled Search Path Element
- CVE-2025-13051 — Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges
- CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l
- CVE-2026-29610 — OpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH Handling
- CVE-2026-24502 — Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit
- CVE-2025-33208 — NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
- CVE-2026-28456 — OpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path Handling