PT-2025-52703 · Sound4 · Sound4 Linkandshare Transmitter

Published

2025-12-22

·

Updated

2025-12-23

·

CVE-2023-53966

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 LinkAndShare Transmitter version 1.1.2
Description SOUND4 LinkAndShare Transmitter version 1.1.2 contains a format string vulnerability. This allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Specifically, manipulating the username environment variable with format string payloads can potentially lead to arbitrary code execution and application crashes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2023-53966

Affected Products

Sound4 Linkandshare Transmitter