Executive brief
IBM Aspera Desktop App, a tool used for high-speed file transfers, contains a vulnerability that could allow an attacker to take control of a user's computer. By placing a malicious file on the system, an attacker can trick the application into running unauthorized code when it starts up. This could lead to the theft of sensitive data or a complete compromise of the affected workstation.
Technical details
IBM Aspera Desktop App versions 1.0.5 through 1.0.19 are vulnerable to arbitrary code execution via DLL hijacking. The application improperly loads Dynamic Link Library (DLL) files during its startup process, potentially using an inherently dangerous function (CWE-242). A local attacker with low privileges can exploit this by placing a malicious DLL in a location searched by the application. Successful exploitation requires a user to launch the application and can result in full system compromise under the context of the running user. IBM has released version 1.1.0 to address this issue.
Affected products
- IBM Aspera Desktop App 1.0.5 - 1.0.19
Timeline
- 2026-07-23: disclosed: Initial publication by IBM
- 2026-07-23: patched: Fixed in version 1.1.0
- 2026-07-30: advisory: NVD publication date