CVE-2023-31747

Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wondershare:filmora:12:*:*:*:*:*:*:*

History

31 May 2023, 18:03

Type Values Removed Values Added
CWE CWE-428
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:wondershare:filmora:12:*:*:*:*:*:*:*
First Time Wondershare
Wondershare filmora
References (MISC) http://wondershare.com - (MISC) http://wondershare.com - Product
References (MISC) http://filmora.com - (MISC) http://filmora.com - Not Applicable
References (MISC) https://packetstormsecurity.com/files/172464/Filmora-12-Build-1.0.0.7-Unquoted-Service-Path.html - (MISC) https://packetstormsecurity.com/files/172464/Filmora-12-Build-1.0.0.7-Unquoted-Service-Path.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2023-05-23 23:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-31747

Mitre link : CVE-2023-31747

CVE.ORG link : CVE-2023-31747


JSON object : View

Products Affected

wondershare

  • filmora
CWE
CWE-428

Unquoted Search Path or Element