Western Digital disclosed CVE-2025-30248, a DLL search order hijacking flaw in the WD Discovery desktop app installer on Windows that can allow local arbitrary code execution. The issue affects WD Discovery 5.2.730 and earlier, where an attacker can place a crafted DLL in the installer’s search path so the legitimate installer loads and executes it, running attacker code with the installer’s privileges; the weakness maps to CWE-427.
Western Digital also reported additional EXE/DLL hijacking issues in the product’s Tiny Installer component, increasing the number of potential local execution paths. Western Digital rated the vulnerability HIGH (reported as CVSS v4.0 8.9), and released WD Discovery 5.3 to address the issues; users are advised to update to 5.3 via the application’s update mechanism or by downloading the latest installer from Western Digital’s official site.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Western Digital publicly disclosed the high-severity WD Discovery vulnerability, stating that DLL search order hijacking in the installer could allow local arbitrary code execution on Windows systems. Public reporting also noted the issue affected WD Discovery 5.2.730 and earlier versions and carried a CVSS v4.0 score of 8.9.
An update entry for CVE-2025-30248 was received by Western Digital PSIRT, adding the vulnerability description, CVSS v4.0 vector, CWE-427 classification, and a reference to the vendor advisory. The flaw was described as a DLL hijacking issue in the WD Discovery installer on Windows.
Western Digital released WD Discovery version 5.3 to remediate CVE-2025-30248 and additional EXE/DLL hijacking weaknesses in the Tiny Installer component. The vendor advised users to upgrade immediately from version 5.2.730 and earlier affected versions.
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. and David Silva responsibly disclosed DLL and related hijacking weaknesses affecting Western Digital's WD Discovery for Windows. The issues included CVE-2025-30248, a DLL search order hijacking flaw in the installer that could enable local arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.