CVE-2025-71178: CWE-427 Uncontrolled Search Path Element in Micron Technology, Inc. Crucial Storage Executive
Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of the intended system library. A local attacker who can convince a victim to run the installer from a directory containing the attacker-supplied DLL can achieve arbitrary code execution with administrator privileges.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-71178) affects Crucial Storage Executive installer versions before 11.08.082025.00. It is a DLL preloading issue (CWE-427) where the installer, running with elevated privileges, loads DLLs from an uncontrolled search path. An attacker with local access can place a malicious DLL in the installer's directory. If the victim executes the installer from that directory, the malicious DLL is loaded instead of the legitimate system DLL, resulting in arbitrary code execution with administrator privileges. The attack requires user interaction and local access, and no known exploits are reported in the wild. The CVSS 4.0 vector indicates local attack vector, low complexity, partial attack requirements, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows a local attacker to execute arbitrary code with administrator privileges on the affected system. This can lead to full system compromise. The attack requires the attacker to have local access and to convince the user to run the installer from a directory containing the malicious DLL. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid running the Crucial Storage Executive installer from untrusted directories and ensure the installer is executed from a trusted location. Monitor vendor communications for updates regarding patches or official mitigations.
CVE-2025-71178: CWE-427 Uncontrolled Search Path Element in Micron Technology, Inc. Crucial Storage Executive
Description
Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of the intended system library. A local attacker who can convince a victim to run the installer from a directory containing the attacker-supplied DLL can achieve arbitrary code execution with administrator privileges.
CVSS v4.0
Score 7.1high
Affected software
Micron Technology, Inc.
Crucial Storage Executive
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-71178) affects Crucial Storage Executive installer versions before 11.08.082025.00. It is a DLL preloading issue (CWE-427) where the installer, running with elevated privileges, loads DLLs from an uncontrolled search path. An attacker with local access can place a malicious DLL in the installer's directory. If the victim executes the installer from that directory, the malicious DLL is loaded instead of the legitimate system DLL, resulting in arbitrary code execution with administrator privileges. The attack requires user interaction and local access, and no known exploits are reported in the wild. The CVSS 4.0 vector indicates local attack vector, low complexity, partial attack requirements, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows a local attacker to execute arbitrary code with administrator privileges on the affected system. This can lead to full system compromise. The attack requires the attacker to have local access and to convince the user to run the installer from a directory containing the malicious DLL. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid running the Crucial Storage Executive installer from untrusted directories and ensure the installer is executed from a trusted location. Monitor vendor communications for updates regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-22T21:24:30.528Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6977ad0e4623b1157cb13175
Added to database: 01/26/2026, 18:06:06 UTC
Last enriched: 05/14/2026, 02:05:11 UTC
Last updated: 09/10/2026, 22:18:49 UTC
Views: 201
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.