CVE-2023-53959
Severity CVSS v4.0:
HIGH
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
19/12/2025
Last modified:
09/04/2026
Description
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:filezilla-project:filezilla_client:3.63.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page


