PatchSiren

Zucchetti S.p.a. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Zucchetti S.p.a. CVE published 2026-08-03

CVE-2026-41447

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:Program Files (x86)Common FilesSSL directory path. This vulnerability can be exploited when FirmaCheck.exe runs automatically at system startup, potentially leading to code execution at the startup process privilege lev [truncated]