First published: Wed Apr 19 2023(Updated: )
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Desktop | <0.62.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28123 is medium.
The affected software versions are UI Desktop for Windows (Version 0.59.1.71 and earlier).
An attacker can exploit CVE-2023-28123 by hijacking VPN credentials while UID VPN is starting.
You can fix CVE-2023-28123 by updating to Version 0.62.3 or later of UI Desktop for Windows.
You can find more information about CVE-2023-28123 at the following link: [https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4](https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4).