HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-44469 — The affected product extracts installation files to a temporary directory with i...
·Source: NIST NVD
Updated:
Executive Summary
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.
Analysis
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation. CVSS Score: 7.8. Published: 2026-05-26T08:16:22.137.