CVE-2026-25191 describes a DLL search path vulnerability in the installer for Digital Arts Inc.'s FinalCode Client. This flaw allows for arbitrary code execution with installer privileges if a malicious DLL is placed in the same directory as the installer and executed. Rated with a CVSS score of 7.8 (HIGH), the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and local access (AV:L), potentially leading to high confidentiality, integrity, and availability impacts. Currently, there are no known public exploits or Metasploit/Nuclei modules, and it is not listed in CISA's KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Digital Arts Inc. | FinalCode Ver.5 Series | prior to 5.43R01CNA affected | |
| Digital Arts Inc. | FinalCode Ver.6 Series | prior to 6.51R01CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.