CVE Database
/

CVE-2025-71178

Back to search

CVE-2025-71178

Published: Jan 26, 2026

Modified: May 14, 2026

PUBLISHED

Description

Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of the intended system library. A local attacker who can convince a victim to run the installer from a directory containing the attacker-supplied DLL can achieve arbitrary code execution with administrator privileges.

VendorProductVersions

Micron Technology, Inc.

Crucial Storage Executive

affected
0 - < 11.08.082025.00

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now