7.8

CVE-2023-29059

Exploit
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
3cx ≫ 3cx Version 18.11.1213 SwPlatform macos
3cx ≫ 3cx Version 18.12.402 SwPlatform macos
3cx ≫ 3cx Version 18.12.407 SwPlatform macos
3cx ≫ 3cx Version 18.12.407 SwPlatform windows
3cx ≫ 3cx Version 18.12.416 SwPlatform macos
3cx ≫ 3cx Version 18.12.416 SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.37% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://cwe.mitre.org/data/definitions/506.html
Technical Description
https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/
Third Party Advisory
Exploit
Technical Description
https://www.3cx.com/blog/news/desktopapp-security-alert/
Vendor Advisory
https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Third Party Advisory
Exploit
https://www.fortinet.com/blog/threat-research/3cx-desktop-app-compromised
Third Party Advisory
Exploit
https://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats
Third Party Advisory
Exploit