CVE-2023-6235

An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution and persistence of arbitrary code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:duetdisplay:duet_display:2.5.9.1:*:*:*:*:windows:*:*

History

21 Nov 2024, 08:43

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/arbitrary-code-execution-duet-display - Third Party Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso/arbitrary-code-execution-duet-display - Third Party Advisory

29 Nov 2023, 16:59

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/arbitrary-code-execution-duet-display - () https://www.incibe.es/en/incibe-cert/notices/aviso/arbitrary-code-execution-duet-display - Third Party Advisory
CPE cpe:2.3:a:duetdisplay:duet_display:2.5.9.1:*:*:*:*:windows:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

21 Nov 2023, 14:08

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-21 13:15

Updated : 2024-11-21 08:43


NVD link : CVE-2023-6235

Mitre link : CVE-2023-6235

CVE.ORG link : CVE-2023-6235


JSON object : View

Products Affected

duetdisplay

  • duet_display
CWE
CWE-427

Uncontrolled Search Path Element