DLL Search Order Hijacking in Wave.exe for Windows 11 by Grandstream Networks
CVE-2025-40979
7HIGH
What is CVE-2025-40979?
A DLL search order hijacking vulnerability exists in the Wave.exe executable for Windows 11, specifically in version 1.27.8. An attacker with local access can exploit this vulnerability by placing a malicious file in the 'C:\Users\AppData\Local\Temp' directory. This could result in the execution of arbitrary code, allowing the attacker to potentially gain persistent access to the system. This security issue is exclusive to Windows 11 and does not affect earlier versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wave 0 < 1.27.11
