CVE-2026-44406
Received Received - Intake
DLL Hijacking in ZTE Cloud PC uSmartView Client

Publication date: 2026-05-07

Last updated on: 2026-05-07

Assigner: ZTE Corporation

Description
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-07
Last Modified
2026-05-07
Generated
2026-05-07
AI Q&A
2026-05-07
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zte cloud_pc_client *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability is a DLL hijacking issue in the ZTE Cloud PC client uSmartView. Specifically, the executable uSmartViewServiceAgent.exe runs with SYSTEM privileges, and due to the DLL hijacking vulnerability, an attacker can trick the system into loading a malicious DLL. This allows the attacker to execute arbitrary code locally with elevated privileges, potentially leading to privilege escalation and memory corruption.


How can this vulnerability impact me? :

This vulnerability can have serious impacts including local arbitrary code execution, which means an attacker can run malicious code on your system. Because the affected process runs with SYSTEM privileges, the attacker can escalate their privileges to the highest level on the system. This can lead to full control over the affected machine, unauthorized actions, and potential memory corruption that could destabilize the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart