CVE-2023-7270
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2024
Last modified:
01/08/2024
Description
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won&#39;t be fixed.<br />
<br />
<br />
<br />
<br />
<br />
The SoftMaker Office and FreeOffice MSI installer files were found to<br />
produce a visible conhost.exe window running as the SYSTEM user when <br />
using the repair function of msiexec.exe. This allows a local, <br />
low-privileged attacker to use a chain of actions, to open a fully <br />
functional cmd.exe with the privileges of the SYSTEM user.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



