CVE-2023-47454: High severity netease cloudmusic vulnerability
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47454?
CVE-2023-47454 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2023-47454?
To fix CVE-2023-47454, ensure that the urlmon.dll file is not present in the current working directory where the application is executed.
Who is affected by CVE-2023-47454?
CVE-2023-47454 affects local users of NetEase CloudMusic version 2.10.4 on Windows systems.
What impact does CVE-2023-47454 have on users?
CVE-2023-47454 allows local users to escalate their privileges, potentially leading to unauthorized access to sensitive data or system controls.
Is there a patch available for CVE-2023-47454?
As of now, there is no official patch released to address CVE-2023-47454, so users should manually mitigate the vulnerability.