Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.