PT-2023-24825 · Microsoft · Windows Qrc Handler
Mason Corkern
·
Publicado
2023-07-14
·
Atualizado
2023-07-26
·
CVE-2023-3434
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jami version 20222284
Description
The issue is related to improper input validation in hyperlink interpretation. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
Recommendations
For Jami version 20222284, consider disabling the hyperlink interpretation feature until a patch is available to prevent exploitation. Restrict access to the Windows QRC Handler to minimize the risk of passing malicious string values. Avoid using custom HTML anchor tags in the Jami messenger until the issue is resolved.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows Qrc Handler