Lucene search

K
cveMitreCVE-2023-38355
HistorySep 19, 2023 - 4:15 p.m.

CVE-2023-38355

2023-09-1916:15:12
CWE-295
mitre
web.nvd.nist.gov
28
cve-2023-38355
minitool movie maker
insecure installation
remote code execution
nvd

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.3%

MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

Affected configurations

Nvd
Node
minitoolmovie_makerMatch7.0
VendorProductVersionCPE
minitoolmovie_maker7.0cpe:2.3:a:minitool:movie_maker:7.0:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.3%

Related for CVE-2023-38355