🔐 CVE Alert

CVE-2026-11958

UNKNOWN 0.0

Local privilege escalation in ANSSI’s DFIR-ORC

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.

CWE CWE-427
Vendor anssi
Product dfir-orc
Published Jun 18, 2026
Last Updated Jun 18, 2026
Stay Ahead of the Next One

Get instant alerts for anssi dfir-orc

Be the first to know when new unknown vulnerabilities affecting anssi dfir-orc are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ANSSI / DFIR-ORC
0 ≤ 10.2.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/local-privilege-escalation-anssis-dfir-orc github.com: https://github.com/DFIR-ORC/dfir-orc/releases/tag/v10.3.0

Credits

Rémi Delabrosse Nicolas Rodrigues