CVE Database
/

CVE-2025-10089

Back to search

CVE-2025-10089

Published: Nov 18, 2025

Modified: Nov 27, 2025

PUBLISHED

CVSS v3.1

7.7

HIGH

Description

Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a local attacker to execute malicious code by having installer to load a malicious DLL. However, if the signer name "Mitsubishi Electric Lighting" appears on the "Digital Signatures" tab of the properties for "MILCO.S Lighting Control.exe", the application is a fixed one. This vulnerability only affects when the installer is run, not after installation. If a user downloads directly from Mitsubishi Electric website and installs the affected product, there is no risk of malicious code being introduced.

VendorProductVersions

Mitsubishi Electric Corporation

MILCO.S Setting Application

affected
All versions

Mitsubishi Electric Corporation

MILCO.S Setting Application (IR)

affected
All versions

Mitsubishi Electric Corporation

MILCO.S Easy Setting Application (IR)

affected
All versions

Mitsubishi Electric Corporation

MILCO.S Easy Switch Application (IR)

affected
All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now