CVE-2023-33965 describes a drive-by command injection vulnerability in the tproxy server component of Brook, a cross-platform programmable network tool. This high-severity vulnerability (CVSS 8.8) allows an attacker to achieve remote code execution by tricking a victim into visiting a malicious webpage that triggers requests to the local tproxy service. While a patch is available in version 20230606, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20230606CPE matchmatch criteria | cpe:2.3:a:txthinking:brook:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.