A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.