CVE-2023-29059
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
30/03/2023
Última modificación:
05/05/2025
Descripción
*** Pendiente de traducción *** 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
CPE | Desde | Hasta |
---|---|---|
cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:* | ||
cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:* | ||
cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:* | ||
cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:* | ||
cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:* | ||
cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:windows:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://cwe.mitre.org/data/definitions/506.html
- https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/
- https://www.3cx.com/blog/news/desktopapp-security-alert/
- https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
- https://www.fortinet.com/blog/threat-research/3cx-desktop-app-compromised
- https://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats
- https://cwe.mitre.org/data/definitions/506.html
- https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/
- https://www.3cx.com/blog/news/desktopapp-security-alert/
- https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
- https://www.fortinet.com/blog/threat-research/3cx-desktop-app-compromised
- https://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats