CVE-2023-45163 is a critical vulnerability affecting the 1E-Exchange-CommandLinePing instruction within the 1E Platform's Network product pack, allowing unauthenticated attackers to achieve arbitrary code execution with SYSTEM privileges on Windows clients due to improper input validation. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating a high impact on confidentiality, integrity, and availability with low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness among security researchers. Organizations are advised to update the Network product pack to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.1CPE matchmatch criteria | cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:* | ||
>= 0, < 18.1CPE match | cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.