CISA advarer om DLL-kapringsfejl i Mitsubishi CNC-software (CVE-2016-2542)
juli 25, 2025 • César Daniel Barreto

CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the advisory is a reminder that the flaw remains unpatched across much of the product line.
The flaw lives in the installer
The root cause is not in Mitsubishi’s own code but in the Flexera InstallShield setup-launcher (through 2015 SP1) that Mitsubishi bundles as the installer for its CNC tools. The launcher uses an untrusted search path (CWE-426 / CWE-427): when it runs, it loads a DLL from its current working directory. If an attacker can plant a malicious DLL alongside the installer — in a downloads folder, a network share, or removable media — the launcher executes the attacker’s code with the user’s privileges.
Local, but realistic
This is a local vulnerability, not a remote one, and it requires a user to run the affected setup-launcher from a directory the attacker can write to. NVD scores it CVSS 7.8 from the InstallShield perspective; CISA re-scored it 7.0 with higher attack complexity in the Mitsubishi CNC context. Either way, it is a realistic path to code execution on engineering workstations.
Fixes and workarounds
Mitsubishi has fixed the issue only in NC Trainer2 and NC Trainer2 plus (version “AC” or later). A long list of other tools — including NC Designer2, NC Configurator2, NC Analyzer2, NC Monitor, NC Trainer, and MS Configurator — will not receive a patch, so operators must rely on workarounds. CISA’s guidance: before running any affected setup-launcher, confirm no DLL is present in its folder; only run installers obtained from official Mitsubishi Electric sources; restrict local access to engineering machines; and keep endpoint protection current.

César Daniel Barreto
César Daniel Barreto er en anerkendt cybersikkerhedsskribent og -ekspert, der er kendt for sin dybdegående viden og evne til at forenkle komplekse cybersikkerhedsemner. Med omfattende erfaring inden for netværks sikkerhed og databeskyttelse bidrager han regelmæssigt med indsigtsfulde artikler og analyser om de seneste cybersikkerhedstendenser og uddanner både fagfolk og offentligheden.