Executive brief
Thermalright TR-VISION HOME, a software utility used to manage LCD displays on computer cooling hardware, contains a security flaw that could allow a local attacker to gain administrative control over a Windows computer. By placing a malicious file in specific folders on the system, an attacker can trick the application into running unauthorized code with high-level system privileges. This could lead to a full system takeover, data theft, or the installation of persistent malware.
Technical details
A DLL search order hijacking vulnerability exists in Thermalright TR-VISION HOME versions up to and including 2.0.5. The application attempts to load required dynamic-link library (DLL) dependencies using the default Windows search order without verifying the integrity or digital signatures of the loaded files. Because the application executes with administrative privileges and searches directories that may be writable by non-privileged users, a local attacker can place a malicious DLL in the search path. When the application is launched, it loads the attacker's code instead of the legitimate library, resulting in arbitrary code execution in an elevated security context.
Affected products
- Thermalright TR-VISION HOME up to and including 2.0.5
Timeline
- 2026-03-16: disclosed
- 2026-03-16: advisory