Junglewise Threat Intelligence

CVE-2026-32679: Japan Media Systems LiveOn Meet and Canon Plugin DLL hijacking in installers

CVE-2026-32679 · Severity: high · CVSS 7.8 · Published 2026-04-23

Executive brief

The installers for LiveOn Meet Client and the Canon Network Camera Plugin for Windows are vulnerable to a security flaw that occurs during the installation process. If a user is tricked into running the installer in a folder containing a malicious file, an attacker can take control of the computer with the same permissions as the user. This could lead to unauthorized software installation, data theft, or full system compromise.

Technical details

A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in the installers for LiveOn Meet Client (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe). The vulnerability stems from the installers searching for required DLLs in the current working directory before system directories. An attacker can achieve arbitrary code execution by placing a malicious DLL in the same directory as the installer and convincing a user to execute the installer. This exploit runs with the privileges of the user who executes the installer, which may include administrative rights if the 'ForAdmin' versions are used. The developer has released updated installers to address this issue.

Affected products

  • Japan Media Systems Corporation LiveOn Meet Client for Windows Installer 1.0.0.0
  • Japan Media Systems Corporation Canon Network Camera Plugin Installer 1.0.0.0

Timeline

  • 2026-04-22: advisory: Initial advisory published by JVN/JPCERT/CC
  • 2026-04-23: disclosed: NVD publication date

References