
Uncontrolled Search Path ElementCVSS 7.3€0
DLL side-loading vulnerability in Sony Music Center for PC Ver. 2.7.2 (Latest version)
resurrect20
Disclosed on HackerOne · June 5, 2026
Publicly disclosed report · by resurrect20
View original on HackerOneOverview The application insecurely searches for the missing DLL file in system PATH environment, allowing an attacker with access to victim's local machine host to achieve arbitrary code execution by implanting a malicious DLL file in any PATH environment.
MITRE reference: https://attack.mitre.org/techniques/T1574/001/
Proof of Concept
- Open Procmon and observe that the application searches for a missing DLL file named "z-bes.dll" in the system PATH variables (e.g. C:\Program Files\Git\cmd\z-bes.dll, C:\Users\supra\Desktop\tools\z-bes.dll etc)
![]()