VendorsAkeorufusall versions
Vulnerabilities

Akeo Rufus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-1010101
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377, CWE-379.
Published 2019-07-19 · Modified
9.8EPSS 0.034
CVE-2017-13083
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
Published 2017-10-18 · Modified
8.1EPSS 0.010
CVE-2019-1010100
Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is: CAPEC-471, CWE-426, CWE-427.
Published 2019-07-19 · Modified
7.8EPSS 0.013
CVE-2026-23988
Rufus has Local Privilege Escalation via TOCTOU Race Condition in Fido Script Handling
Published 2026-01-22 · Analyzed
7.3EPSS 0.002