PT-2023-32446 · 1E · 1E Exchange End-User Interaction
Published
2023-11-06
·
Updated
2025-05-20
·
CVE-2023-5964
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
1E Exchange End-User Interaction product pack versions prior to 7.1
Description
The 1E-Exchange-DisplayMessage instruction does not properly validate the
Caption or Message parameters, allowing for arbitrary code execution with SYSTEM permissions. This issue only affects Windows clients.Recommendations
To remediate this issue, delete the instruction “Show dialogue with caption %Caption% and message %Message%” from the list of instructions in the Settings UI, and replace it with the new instruction 1E-Exchange-ShowNotification instruction available in the updated End-User Interaction product pack, which should show as “Show %Type% type notification with header %Header% and message %Message%” with a version of 7.1 or above.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
1E Exchange End-User Interaction