PeaZip Library dragdropfilesdll.dll uncontrolled search path
CVE-2023-6891

7.8HIGH

Key Information:

Vendor

Peazip

Status
Vendor
CVE Published:
17 December 2023

What is CVE-2023-6891?

A local file manipulation vulnerability has been identified in PeaZip version 9.4.0, specifically within the dragdropfilesdll.dll component of the Library Handler. The flaw enables attackers to exploit an uncontrolled search path, potentially allowing unauthorized file access. This issue necessitates local execution for exploitation. Users are strongly advised to upgrade to PeaZip version 9.6.0, where this vulnerability has been addressed. The vendor confirmed the flaw's existence and has promptly released a patch to resolve it.

Affected Version(s)

PeaZip 9.4.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tfhm (VulDB User)
.