CVE-2025-71178 - CVE House
Back to Database
Status published High CVE-2025-71178

Crucial Storage Executive < 11.08.082025.00 Installer DLL Preloading LPE

Vulnerability Description

Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which can cause a malicious DLL placed alongside the installer to be loaded instead of the intended system library. A local attacker who can convince a victim to run the installer from a directory containing the attacker-supplied DLL can achieve arbitrary code execution with administrator privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71178

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.

Affected Vendor

Micron Technology, Inc.

View all reports →

Affected Software

Crucial Storage Executive
Vulnerable Versions:
0

Timeline

Official Publish: January 26th, 2026
Last Modified: May 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)