CVE-2023-7270

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2024
Last modified:
01/08/2024

Description

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won&amp;#39;t be fixed.<br /> <br /> <br /> <br /> <br /> <br /> The SoftMaker Office and FreeOffice MSI installer files were found to<br /> produce a visible conhost.exe window running as the SYSTEM user when <br /> using the repair function of msiexec.exe. This allows a local, <br /> low-privileged attacker to use a chain of actions, to open a fully <br /> functional cmd.exe with the privileges of the SYSTEM user.