An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the product is executed.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.