CVE-2023-53875 is a high-severity remote code execution vulnerability affecting GOM Player version 2.3.90.5360. Attackers can exploit this flaw via DNS spoofing, redirecting users through a malicious URL shortcut and WebDAV to execute a reverse shell, achieving complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, its high CVSS score of 8.8 and FAUCET Risk Score of 90/100 indicate a significant potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.90.5360CPE matchmatch criteria | cpe:2.3:a:gomlab:gom_player:2.3.90.5360:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.