CVE-2025-61161HIGH 8.4EPSS p3.6%

CVE-2025-61161CVE-2025-61161

Description

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.

Scoring

CVSS 3.18.4 (HIGH)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.14% probability of exploitation · percentile 3.6% · 2026-06-17T12:03:21Z
Published2025-10-29
Last modified2026-04-15

Underlying weaknesses· 1

CWE-427

References

  1. https://www.evope.tech/
  2. https://xavilok.es/dll-hijacking-in-evopeservice--system-to-gui-shell

1

TypeTargetConfidenceTier
WeaknessUncontrolled Search Path Elementcwe-4270%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-69784
CVE
CVE-2026-28704
CVE
CVE-2025-69258
CVE
CVE-2025-33067
CVE
CVE-2025-49155
CVE
CVE-2025-56577
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.