CVE-2023-45883

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2023
Last modified:
12/09/2024

Description

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enghouse:qumu:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.63 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*