important · RCE / zero-click
Any web page can make a vulnerable SConnect installation load an unsigned DLL.
Affects
Thales SConnect, browser-to-native middleware used by electronic-identity, signing and financial-authentication products on Windows workstations.
A failed RSA operation leaves attacker-influenced data in an uninitialized verification buffer, bypassing the origin token and both package-signature layers.
Detail and 3 sources
The researcher demonstrated the path in Edge with an unsigned message-box DLL.