CVE-2023-29059 describes a supply chain attack where malicious code was embedded in specific versions of the 3CX DesktopApp for Windows and macOS, affecting versions 18.12.407 and 18.12.416 for Windows, and multiple versions including 18.11.1213 through 18.12.416 for macOS. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk with high confidentiality, integrity, and availability impacts, though it requires local access and low privileges. The vulnerability has been actively exploited in the wild, notably by North Korean threat actors targeting cryptocurrency firms, and has garnered substantial community discussion and media coverage despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.11.1213CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:* | ||
18.12.402CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:* | ||
18.12.407CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:* | ||
18.12.407CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:* | ||
18.12.416CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.