CVE-2026-4255 is a local privilege escalation vulnerability in Thermalright TR-VISION HOME for Windows (64-bit), affecting versions up to and including 2.0.5. The application loads certain DLL dependencies using the default Windows DLL search order rather than restricting resolution to trusted, application-controlled locations. Because the search path includes directories that may be writable by non-privileged users, an attacker can place a malicious DLL with the same name as a legitimate dependency in a searched location that is resolved before a trusted system directory. When TR-VISION HOME is launched, the malicious library is loaded through DLL side-loading and attacker-controlled code executes in the application's security context. The issue is compounded by the absence of effective controls on DLL loading locations and by the lack of integrity or signature verification for loaded libraries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept for CVE-2026-4255 affecting Thermalright TR-VISION HOME <= 2.0.5 on Windows x64. It contains two files: a README describing the vulnerability, exploitation steps, and mitigation guidance; and a single C source file, poc/Ftd2xx.c, implementing the malicious replacement DLL. The exploit is not framework-based. The core capability is local privilege escalation via DLL side-loading / search-order hijacking. TR-VISION HOME loads Ftd2xx.dll without a fully qualified path and runs elevated, allowing a low-privileged attacker to plant a crafted Ftd2xx.dll in a user-writable directory that appears on PATH. When the victim launches the application and approves elevation, the attacker DLL is loaded into the elevated process and its DllMain executes. The PoC payload is benign but functional: on DLL_PROCESS_ATTACH it disables thread notifications, queries the current token to determine whether the process is elevated, writes a proof file to C:\Users\Public\CVE-2026-4255_pwned.txt containing the PID and elevation status, and displays a MessageBoxA popup confirming successful elevated execution. There is no network communication, command-and-control, persistence, or shell-spawning logic in the provided code. The exploit therefore demonstrates code execution with administrative privileges but stops short of delivering a more advanced post-exploitation payload. Repository structure is minimal and purpose-built: README.md documents the vulnerability mechanics, prerequisites, compilation commands for MinGW/MSVC, example writable PATH planting locations, trigger conditions, and expected results; poc/Ftd2xx.c is the sole executable artifact and main entry point for the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.