CVE-2023-1186 is a null pointer dereference vulnerability found in FabulaTech Webcam for Remote Desktop version 2.8.42, specifically within the ftwebcam.sys library's IOCTL Handler. This flaw affects both FabulaTech Webcam for Remote Desktop and Microsoft Windows when the product is installed. With a CVSS score of 5.5 (Medium), it requires local access and low privileges to exploit, leading to a high impact on availability, though confidentiality and integrity are not affected. While the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available Metasploit, Nuclei, or ExploitDB modules, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.42CPE matchmatch criteria | cpe:2.3:a:fabulatech:webcam_for_remote_desktop:2.8.42:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.