CVE-2023-42526
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-42526 is a newly disclosed vulnerability that impacts various WithSecure products, including WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0, Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1. Hackers can exploit this issue by sending crafted data files for decompression, resulting in a remote crash of the scanning engine. Successful attacks may lead to denial-of-service conditions or potential escalation of privileges. Users are advised to update their WithSecure products to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WithSecure