ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.

Project Subscriptions

Vendors Products
Zxcloud Irai Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 08 May 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:*

Thu, 07 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxcloud Irai
Vendors & Products Zte
Zte zxcloud Irai

Thu, 07 May 2026 07:30:00 +0000

Type Values Removed Values Added
Description ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.
Title DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-05-07T12:58:05.755Z

Reserved: 2026-05-06T08:50:27.676Z

Link: CVE-2026-44406

cve-icon Vulnrichment

Updated: 2026-05-07T12:58:00.602Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-07T08:16:00.830

Modified: 2026-05-08T16:59:09.333

Link: CVE-2026-44406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T08:30:25Z

Weaknesses