
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2516 is an uncontrolled search path (DLL hijacking) vulnerability affecting Unidocs ezPDF DRM Reader and ezPDF Reader versions 2.0 and 3.0.0.4. The flaw resides in an unknown code path within the SHFOLDER.dll library, where improper handling of the DLL search path allows a local attacker to substitute a malicious DLL. It was published on February 15, 2026, and carries a CVSS v3.1 base score of 7.0 (High) and a CVSS v4.0 base score of 7.3 (High) (Feedly, VulDB).
The vulnerability is classified under CWE-426 (Untrusted Search Path) and CWE-427 (Uncontrolled Search Path Element). When ezPDF DRM Reader or ezPDF Reader loads SHFOLDER.dll, it does not enforce a fully qualified or trusted path, allowing an attacker with local access to place a malicious DLL in a directory that is searched before the legitimate system location. Exploitation requires low privileges and no user interaction, but is rated high complexity, consistent with MITRE ATT&CK techniques T1574.001 (DLL Search Order Hijacking) and T1574.007 (Path Interception by PATH Environment Variable). A proof-of-concept exploit is publicly available (Feedly, VulDB).
Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability on the affected system, as the malicious DLL executes in the context of the vulnerable application. An attacker could achieve arbitrary code execution, access sensitive data processed by the PDF reader (including DRM-protected content), or cause application crashes. The scope is limited to the local system, with no direct lateral movement capability, though code execution could serve as a stepping stone for privilege escalation or further compromise (Feedly).
A proof-of-concept exploit is publicly available, raising the risk of weaponization despite the local-only attack vector and high complexity rating. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of widespread exploitation. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, VulDB).
SHFOLDER.dll (e.g., application directory, current working directory, directories in the PATH environment variable) using tools such as Process Monitor (Procmon) from Sysinternals.SHFOLDER.dll that executes attacker-controlled code (e.g., a reverse shell or credential dumper) while optionally forwarding legitimate exports to avoid crashes.SHFOLDER.dll into a directory that is searched before the legitimate Windows system directory (e.g., the application's installation folder or a writable directory in the PATH), requiring only low-privilege local write access.SHFOLDER.dll in the ezPDF application installation directory or any directory listed in the system/user PATH environment variable; file hash mismatch compared to the legitimate Microsoft SHFOLDER.dll.cmd.exe, powershell.exe, network tools); unexpected network connections originating from the ezPDF Reader process.SHFOLDER.dll; Sysmon Event ID 7 (Image Loaded) entries showing SHFOLDER.dll loaded from a path other than %SystemRoot%\System32\.Unidocs recommends upgrading to the latest version of ezPDF DRM Reader or ezPDF Reader, stating that similar DLL search path vulnerability patterns have been addressed in prior security updates. As a workaround, administrators should ensure the application's installation directory and all directories in the PATH environment variable are not writable by unprivileged users. Additionally, enabling Windows Safe DLL Search Mode and using application whitelisting (e.g., AppLocker) can reduce the risk of DLL hijacking attacks (Feedly, VulDB).
The vulnerability received coverage from automated security aggregators and community feeds, including VulDB, Vulners, and CIRCL. The VulDB Mastodon account (@vuldb) posted a notification, and the offseq threat radar platform flagged it for tracking. No notable independent researcher commentary or major media coverage has been identified beyond standard aggregation (VulDB Mastodon, offseq).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."