Fiche vulnérabilité
CVE-2023-6235 : faille élevée duetdisplay duet display (CVSS 7.8)
Description
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution and persistence of arbitrary code.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 21 nov. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- duetdisplay duet display