CVE-2023-53965

HIGHCVSS 8.6/10EPSS 0.20%

Last modified

CVE-2023-53965 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
8.6/10

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.20%

10.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Sound4Playout Ula8 Firmware4.1.102
Sound4Stream X8 Firmware4.1.102
Sound4Stream X4 Firmware4.1.102
Sound4Stream X2 Firmware4.1.102
Sound4Wm2 Firmware4.1.102
Sound4Ip Connect Firmware4.1.102
Sound4Voice Ula8 Firmware4.1.102
Sound4Voice Ula4 Firmware4.1.102
Sound4Voice Ula2 Firmware4.1.102
Sound4Big Voice Firmware4.1.102
Sound4Pulse Eco Firmware4.1.102
Sound4Impact Eco Firmware4.1.102
Sound4First Firmware4.1.102
Sound4Pulse Firmware4.1.102
Sound4Impact Firmware4.1.102

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2023-53965?
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.
How severe is CVE-2023-53965?
CVE-2023-53965 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2023-53965?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-53965?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST