CVE-2023-45161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/11/2023
Last modified:
12/06/2025

Description

The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This instruction only runs on Windows clients.<br /> <br /> To remediate this issue download the updated Network product pack from the 1E Exchange and update the 1E-Exchange-URLResponseTime instruction to v20.1 by uploading it through the 1E Platform instruction upload UI

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:* 20.1 (excluding)