Executive brief
RATOC RAID Monitoring Manager is a utility used to manage and monitor external storage hardware. A security flaw in its installer allows an attacker to trick a user into running a malicious file. If successful, the attacker could gain full administrative control over the computer, potentially leading to data theft or system compromise.
Technical details
The installer for RATOC RAID Monitoring Manager for Windows contains an uncontrolled search path element (CWE-427). The application searches the current directory to load specific DLLs during the installation process. An attacker can exploit this by placing a malicious DLL in the same directory as the installer and convincing a user to execute the installer. If successful, the crafted DLL is loaded and executed with the privileges of the installer, typically administrative, allowing for full system compromise. This issue is resolved in version 2.00.009.260220.
Affected products
- RATOC Systems, Inc. RAID Monitoring Manager for Windows Prior to 2.00.009.260220
Timeline
- 2025-08-29: other: Initial vendor notification/internal tracking date
- 2026-03-18: patched: Vendor update regarding fix availability
- 2026-03-26: advisory: Public disclosure via JVN and NVD