CVE-2025-10089
Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a local attacker to execute malicious code by having installer to load a malicious DLL. However, if the signer name "Mitsubishi Electric Lighting" appears on the "Digital Signatures" tab of the properties for "MILCO.S Lighting Control.exe", the application is a fixed one.
Read full descriptionShow less
This vulnerability only affects when the installer is run, not after installation. If a user downloads directly from Mitsubishi Electric website and installs the affected product, there is no risk of malicious code being introduced.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Base score: 7.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.14%
- Percentile among all scored CVEs: 3
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1203Exploitation for Client Executionexecution85 % - Primary impact
T1574.007Path Interception by PATH Environment Variablestealth · execution80 % - Secondary impact
T1059Command and Scripting Interpreterexecution75 %
CWE-427 (búsqueda descontrolada en ruta) durante la instalación requiere interacción del usuario (UI:R) y acceso local (AV:L). El atacante carga un DLL malicioso, lo que constituye secuestro de dependencias (T1574.007) que permite ejecución de código arbitrario (T1059). La vulnerabilidad solo se act
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (3)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-427
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-10089",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-10089",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-11-18T14:24:34.564560Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1
}
]
},
"affected": [
{
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"affectedData": [
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MILCO.S Setting Application",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MILCO.S Setting Application (IR)",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MILCO.S Easy Setting Application (IR)",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Mitsubishi Electric Corporation",
"product": "MILCO.S Easy Switch Application (IR)",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-11-18T08:15:49.010",
"references": [
{
"url": "https://jvn.jp/vu/JVNVU97181602/",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
},
{
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-015_en.pdf",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a local attacker to execute malicious code by having installer to load a malicious DLL. However, if the signer name \"Mitsubishi Electric Lighting\" appears on the \"Digital Signatures\" tab of the properties for \"MILCO.S Lighting Control.exe\", the application is a fixed one. This vulnerability only affects when the installer is run, not after installation. If a user downloads directly from Mitsubishi Electric website and installs the affected product, there is no risk of malicious code being introduced."
}
],
"lastModified": "2026-06-17T08:27:39.987",
"sourceIdentifier": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}