Uncontrolled Search Path Element Remote Code Execution Vulnerability
CVE-2023-44439
8.8HIGH
What is CVE-2023-44439?
The vulnerability arises from the improper handling of various file types by Ashlar-Vellum Xenon, which allows the software to load libraries from unsecured locations. This flaw presents a significant risk, as it enables remote attackers to execute arbitrary code within the current process context. Exploitation of this vulnerability necessitates user interaction, requiring the target to either access a malicious webpage or open a compromised file. This issue underscores the importance of securing library paths and addressing vulnerabilities that necessitate user input for successful exploitation.
Affected Version(s)
Xenon Xenon v12 Beta Build 1204.68