CVE-2023-34407

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 22

Summary

CVE-2023-34407 is a vulnerability affecting Harbinger Offline Player version 4.0.6.0.2. This issue permits an attacker to perform directory traversal attacks against the OfflinePlayerService.exe component, exploiting the vulnerability when a URL containing '..\' is processed. Successful exploitation grants the attacker system-level access, potentially leading to significant security risks. It is crucial for users to apply the necessary patches or updates to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share