CVE-2023-54330: Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow
Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-54330?
CVE-2023-54330 is classified as a critical severity vulnerability due to the potential for unauthenticated remote code execution.
How do I fix CVE-2023-54330?
To fix CVE-2023-54330, update Inbit Messenger to version 4.10.0 or later where the vulnerability is patched.
Who is affected by CVE-2023-54330?
CVE-2023-54330 affects all versions of Inbit Messenger from 4.6.0 to 4.9.0.
What type of vulnerability is CVE-2023-54330?
CVE-2023-54330 is a remote stack-based buffer overflow vulnerability.
Can attackers exploit CVE-2023-54330 without authentication?
Yes, attackers can exploit CVE-2023-54330 without authentication by sending specially crafted network packets.