CVE-2023-27362: 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 3CX. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-20026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27362?
The severity of CVE-2023-27362 is classified as high due to its potential for local privilege escalation.
How do I fix CVE-2023-27362?
To fix CVE-2023-27362, it is recommended to update the 3CX software to the latest version provided by the vendor.
Who is affected by CVE-2023-27362?
CVE-2023-27362 affects installations of 3CX software that have not been patched against this vulnerability.
What kind of attack does CVE-2023-27362 facilitate?
CVE-2023-27362 facilitates local privilege escalation attacks, enabling attackers to gain higher-level permissions on the affected system.
Is user interaction required to exploit CVE-2023-27362?
Yes, an attacker must first gain the ability to execute low-privileged code on the target system to exploit CVE-2023-27362.