Micco develops a suite of legacy compression and archive-utility libraries including UnLHA32.dll, LHMelting, UnARJ32.dll, and LMLZH32.dll that decompress and extract archived files across Windows environments. The recurring vulnerability signal centers on untrusted search path weaknesses in these utilities, a characteristic risk in older decompression tools where library loading and file-search order can be manipulated by a local attacker. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Micco over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5913HIGH Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an | Feb 13, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5912HIGH Untrusted search path vulnerability in the installer of UNARJ32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier) allows an attacker to gain privileges via a Trojan horse DLL i | Feb 13, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5911HIGH Untrusted search path vulnerability in the installer of UNLHA32.DLL (UNLHA32.DLL for Win32 Ver 2.67.1.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in | Feb 13, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-16190HIGH Untrusted search path vulnerability in UNARJ32.DLL for Win32, LHMelting for Win32, and LMLzh32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier, LHMelting for Win32 Ver 1.65.3. | Feb 13, 2019 | 7.8 | 23 | NO | NO |
CVE-2018-16189HIGH Untrusted search path vulnerability in Self-Extracting Archives created by UNLHA32.DLL prior to Ver 3.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecif | Feb 13, 2019 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Micco.
Media articles that mention a CVE ID that affects a product developed by Micco — matched by CVE ID, not by vendor name.