Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.