CVE-2026-11958
Local privilege escalation in ANSSI’s DFIR-ORC
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and executed from that location with administrative privileges, the malicious library can be loaded automatically, allowing the attacker to gain administrator privileges on the affected machine.
| CWE | CWE-427 |
| Vendor | anssi |
| Product | dfir-orc |
| Published | Jun 18, 2026 |
| Last Updated | Jun 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for anssi dfir-orc
Be the first to know when new unknown vulnerabilities affecting anssi dfir-orc are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
ANSSI / DFIR-ORC
0 ≤ 10.2.7
References
Credits
Rémi Delabrosse Nicolas Rodrigues