CVE-2023-29059
Published · Updated
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 7.8epss 4.4%
from disclosure to weapon
Published on NVDMar 30
VulnCheckMar 29
exploitation probability
4.4%top 9% of all CVEs
observed exploitation
yesVulnCheck
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aReferences
https://cwe.mitre.org/data/definitions/506.htmlhttps://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/https://www.3cx.com/blog/news/desktopapp-security-alert/https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/https://www.fortinet.com/blog/threat-research/3cx-desktop-app-compromisedhttps://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats