PT-2023-30456 · Netease+1 · Netease Cloudmusic+1

Published

2023-11-30

·

Updated

2023-12-06

·

CVE-2023-47454

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetEase CloudMusic version 2.10.4
Description An Untrusted search path issue allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
Recommendations For NetEase CloudMusic version 2.10.4, consider restricting access to the urlmon.dll file in the current working directory until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2023-47454

Affected Products

Netease Cloudmusic
Urlmon.Dll