GHSA-gmvp-63rm-744wHighCVSS 7.3
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process...
🔗 CVE IDs covered (1)
📋 Description
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-102262
- https://mediaserver.newellrubbermaid.com/industrial/Help/win/en/Content/What's%20New.htm
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-275-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-102262
- https://www.dymo.com/support?cfid=user-guide
- https://github.com/advisories/GHSA-gmvp-63rm-744w