7.8
CVE-2023-6235
- EPSS 0.26%
- Veröffentlicht 21.11.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:25
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Arbitrary code execution in Duet Display
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution and persistence of arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Duetdisplay ≫ Duet Display Version2.5.9.1 SwPlatformwindows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.171 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| cve-coordination@incibe.es | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
https://www.incibe.es/en/incibe-cert/notices/aviso/arbitrary-code-execution-duet-display