PT-2023-32446 · 1E · 1E Exchange End-User Interaction

Published

2023-11-06

·

Updated

2025-05-20

·

CVE-2023-5964

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1E Exchange End-User Interaction product pack versions prior to 7.1
Description The 1E-Exchange-DisplayMessage instruction does not properly validate the Caption or Message parameters, allowing for arbitrary code execution with SYSTEM permissions. This issue only affects Windows clients.
Recommendations To remediate this issue, delete the instruction “Show dialogue with caption %Caption% and message %Message%” from the list of instructions in the Settings UI, and replace it with the new instruction 1E-Exchange-ShowNotification instruction available in the updated End-User Interaction product pack, which should show as “Show %Type% type notification with header %Header% and message %Message%” with a version of 7.1 or above.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-5964

Affected Products

1E Exchange End-User Interaction