Executive brief
The installer for HYPER SBI 2, a financial trading application, contains a security flaw in how it handles system files during installation. If an attacker places a malicious file in the same folder as the installer, they can gain full control over the user's computer when the installation starts. This could lead to the theft of sensitive financial data or the installation of persistent malware on the user's system.
Technical details
The HYPER SBI 2 installer is vulnerable to an uncontrolled search path element (CWE-427), commonly known as DLL hijacking. The application fails to use secure absolute paths when loading required Dynamic Link Libraries, causing it to search the current working directory. An attacker can exploit this by placing a malicious DLL with a specific name in the same directory as the installer (e.g., via a downloaded ZIP archive or a shared network folder). When a user executes the installer, the malicious code is loaded and executed with the user's current privileges. The vulnerability is addressed in version 3.20.0 and later.
Affected products
- SBI SECURITIES Co.,Ltd. HYPER SBI 2 versions before 3.20.0
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory