ZDI-CAN-20026: ZDI-23-1153: 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of 3CX. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20026?
ZDI-CAN-20026 has been classified with high severity due to its potential for local privilege escalation.
How do I fix ZDI-CAN-20026?
To fix ZDI-CAN-20026, it is recommended to update to the latest version of 3CX that addresses this vulnerability.
Who is affected by ZDI-CAN-20026?
ZDI-CAN-20026 affects installations of the 3CX software that have not been updated to secure versions.
What type of vulnerability is ZDI-CAN-20026?
ZDI-CAN-20026 is a local privilege escalation vulnerability, requiring prior access to the system.
Can remote attackers exploit ZDI-CAN-20026?
No, ZDI-CAN-20026 can only be exploited by local attackers who have already executed low-privileged code on the system.