HIGH · 8.4

CVE-2023-53965

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit ...

Vulnerability Description

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

CVSS Score

8.4

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Sound4Impact Firmware4.1.102
Sound4Impact-
Sound4Pulse Firmware4.1.102
Sound4Pulse-
Sound4First Firmware4.1.102
Sound4First-
Sound4Impact Eco Firmware4.1.102
Sound4Impact Eco-
Sound4Pulse Eco Firmware4.1.102
Sound4Pulse Eco-
Sound4Big Voice Firmware4.1.102
Sound4Big Voice-
Sound4Voice Ula2 Firmware4.1.102
Sound4Voice Ula2-
Sound4Voice Ula4 Firmware4.1.102
Sound4Voice Ula4-
Sound4Voice Ula8 Firmware4.1.102
Sound4Voice Ula8-
Sound4Ip Connect Firmware4.1.102
Sound4Ip Connect-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-53965?

CVE-2023-53965 is a vulnerability with a CVSS score of 8.4 (HIGH). SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit ...

How severe is CVE-2023-53965?

CVE-2023-53965 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-53965?

Check the references section above for vendor advisories and patch information. Affected products include: Sound4 Impact Firmware, Sound4 Impact, Sound4 Pulse Firmware, Sound4 Pulse, Sound4 First Firmware.