A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.