Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-29059

28
FAUCET Score

CVE-2023-29059 describes a supply chain attack where malicious code was embedded in specific versions of the 3CX DesktopApp for Windows and macOS, affecting versions 18.12.407 and 18.12.416 for Windows, and multiple versions including 18.11.1213 through 18.12.416 for macOS. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk with high confidentiality, integrity, and availability impacts, though it requires local access and low privileges. The vulnerability has been actively exploited in the wild, notably by North Korean threat actors targeting cryptocurrency firms, and has garnered substantial community discussion and media coverage despite a lack of public exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
18.11.1213CPE matchmatch criteria
cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:*
18.12.402CPE matchmatch criteria
cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:*
18.12.407CPE matchmatch criteria
cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:*
18.12.407CPE matchmatch criteria
cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:*
18.12.416CPE matchmatch criteria
cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.37%
Probability of exploitation in next 30 days
EPSS Percentile
90.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0437 is in the 98th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cwe.mitre.org / data/definitions/506.html
Technical Description
news.sophos.com / en-us/2023/03/29/3cx-dll-sideloading-attack
ExploitTechnical DescriptionThird Party Advisory
3cx.com / blog/news/desktopapp-security-alert
Vendor Advisory
crowdstrike.com / blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers
ExploitThird Party Advisory
fortinet.com / blog/threat-research/3cx-desktop-app-compromised
ExploitThird Party Advisory
huntress.com / blog/3cx-voip-software-compromise-supply-chain-threats
ExploitThird Party Advisory