DLL Search Order Hijacking in Wave.exe for Windows 11 by Grandstream Networks
CVE-2025-40979
7HIGH
What is CVE-2025-40979?
A DLL search order hijacking vulnerability exists in the Wave.exe executable for Windows 11, specifically in version 1.27.8. An attacker with local access can exploit this vulnerability by placing a malicious file in the 'C:\Users\AppData\Local\Temp' directory. This could result in the execution of arbitrary code, allowing the attacker to potentially gain persistent access to the system. This security issue is exclusive to Windows 11 and does not affect earlier versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wave 0 < 1.27.11
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alexander Huaman Jaimes
