CVE-2023-5964 is a high-severity vulnerability affecting the 1E-Exchange-DisplayMessage instruction within the 1E End-User Interaction product pack. This flaw allows for arbitrary code execution with SYSTEM privileges on Windows clients due to improper validation of Caption or Message parameters. The CVSS score is 7.2 (High), indicating a network-based attack with low complexity, requiring high privileges, and leading to high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity community. Remediation involves deleting the vulnerable instruction and replacing it with the updated 1E-Exchange-ShowNotification instruction (version 7.1 or above).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 23CPE match | cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:* | ||
< 23.0CPE matchmatch criteria | cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.