PT-2023-16681 · Microsoft+1 · Wsh Jscript Handler+1

Tom23

·

Publicado

2023-02-24

·

Atualizado

2024-05-17

·

CVE-2023-1004

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MarkText versions up to 0.17.1
Description A critical vulnerability has been found in MarkText, affecting an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection, requiring local access to approach this attack. The exploit has been disclosed to the public and may be used.
Recommendations For MarkText versions up to 0.17.1, update to a version later than 0.17.1 to resolve the issue. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1004

Produtos afetados

Marktext
Wsh Jscript Handler