Executive brief
Bytello Share is a screen mirroring tool used for large displays. The Windows installer for this software contains a security flaw that allows it to inadvertently load malicious files if they are placed in the same folder as the installer. If an attacker tricks a user into running the installer in a directory containing a malicious file, they could gain full control over the user's computer.
Technical details
The Bytello Share (Windows Edition) installer is vulnerable to an uncontrolled search path element (CWE-427), commonly known as DLL hijacking. The installer executable does not specify the absolute path when loading certain Dynamic Link Libraries (DLLs), causing it to search the current working directory. An attacker can exploit this by placing a malicious DLL with a specific name in the same directory as the installer (e.g., via a downloaded ZIP archive or a shared network folder). When a user executes the installer, the malicious code is loaded and executed with the privileges of that user. The issue is resolved in version 5.13.0.4246, which is distributed as an MSI package.
Affected products
- Bytello Bytello Share (Windows Edition) installer prior to 5.13.0.4246
Timeline
- 2026-05-13: disclosed: Vulnerability disclosed via JVN and NVD.
- 2026-05-13: patched: Version 5.13.0.4246 released as an MSI package to address the issue.