CVE-2023-34407
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 22
Summary
CVE-2023-34407 is a vulnerability affecting Harbinger Offline Player version 4.0.6.0.2. This issue permits an attacker to perform directory traversal attacks against the OfflinePlayerService.exe component, exploiting the vulnerability when a URL containing '..\' is processed. Successful exploitation grants the attacker system-level access, potentially leading to significant security risks. It is crucial for users to apply the necessary patches or updates to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- HRG) Group Inc.