CVE Explorer
CVE-2026-33156
ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the Windows System32 directory, allowing arbitrary code execution in the user's context. This is especially impactful because ScreenToGif is primarily distributed as a portable application intended to be run from user-writable loca
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-427","description":"CWE-427: Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-426","description":"CWE-426: Untrusted Search Path","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"ScreenToGif","vendor":"NickeManarin","versions":[{"status":"affected","version":"<= 2.42.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-427","description":"CWE-427: Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-426","description":"CWE-426: Untrusted Search Path","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/NickeManarin/ScreenToGif/security/advisories/GHSA-3fmj-j696-9mg2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/adp/0/references/0
{"name":"https://github.com/NickeManarin/ScreenToGif/security/advisories/GHSA-3fmj-j696-9mg2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/NickeManarin/ScreenToGif/security/advisories/GHSA-3fmj-j696-9mg2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1719e1612e3732649383817d4556b805dec1c04f03e73bd80ae1997359168b12 · sha256:9a8819fb50a974b9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.