CVE-2023-49147
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Dec 19, 2023
Updated: Jan 2, 2024
Summary
CVE-2023-49147 is a vulnerability affecting PDF24 Creator 11.14.0. The issue lies in the msi installer file's configuration, which inadvertently reveals a cmd.exe window during the repair function of msiexec.exe. An unprivileged local attacker can exploit this vulnerability by employing a sequence of actions, such as an oplock on faxPrnInst.log, to launch a SYSTEM cmd.exe and potentially gain elevated privileges. This poses a significant risk to systems where PDF24 Creator is installed, particularly if users have the repair function enabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share