Unquoted Service Path Vulnerability in Wondershare Filmora 12
CVE-2023-31747

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
23 May 2023

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2023-31747?

A vulnerability exists in Wondershare Filmora 12 that can be exploited due to an unquoted service path in the NativePushService component. This weakness allows attackers to execute processes with elevated privileges, potentially leading to unauthorized actions on the affected system. Users of Filmora 12 should be aware of this risk and take necessary precautions to mitigate exposure.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

.