PT-2023-24825 · Microsoft · Windows Qrc Handler
Mason Corkern
·
Published
2023-07-14
·
Updated
2023-07-26
·
CVE-2023-3434
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jami version 20222284
Description
The issue is related to improper input validation in hyperlink interpretation. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
Recommendations
For Jami version 20222284, consider disabling the hyperlink interpretation feature until a patch is available to prevent exploitation. Restrict access to the Windows QRC Handler to minimize the risk of passing malicious string values. Avoid using custom HTML anchor tags in the Jami messenger until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Qrc Handler