CVE-2023-45160 is a high-severity vulnerability affecting the 1E Client, allowing an authenticated, low-privileged attacker to achieve high impact to confidentiality, integrity, and availability. By replacing legitimate instruction resource files with malicious scripts in the client's temporary directory, an attacker could execute arbitrary code. While no public exploits or active exploitation have been observed, the vulnerability carries a CVSS score of 8.8 and has been addressed in patch Q23094 for Windows and updated versions of the Mac Client.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1.2.62CPE matchmatch criteria | cpe:2.3:a:1e:client:8.1.2.62:*:*:*:*:windows:*:* | ||
8.4.1.159CPE matchmatch criteria | cpe:2.3:a:1e:client:8.4.1.159:*:*:*:*:windows:*:* | ||
9.0.1.88CPE matchmatch criteria | cpe:2.3:a:1e:client:9.0.1.88:*:*:*:*:windows:*:* | ||
23.7.1.151CPE matchmatch criteria | cpe:2.3:a:1e:client:23.7.1.151:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.