CVE-2023-29059

Published on: Not Yet Published

Last Modified on: 04/10/2023 04:29:00 PM UTC

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of 3cx from 3cx contain the following vulnerability:

3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.

  • CVE-2023-29059 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVE References

Description Tags Link
CWE - CWE-506: Embedded Malicious Code (4.8) cwe.mitre.org
text/html
URL Logo MISC cwe.mitre.org/data/definitions/506.html
3CX VoIP Software Compromise & Supply Chain Threats www.huntress.com
text/html
URL Logo MISC www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats
Update 2: 3CX users under DLL-sideloading attack: What you need to know – Sophos News Exploit
Technical Description
Third Party Advisory
news.sophos.com
text/html
URL Logo MISC news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/
3CX Security Alert for Electron Windows App | Desktop App www.3cx.com
text/html
URL Logo MISC www.3cx.com/blog/news/desktopapp-security-alert/
3CX Desktop App Compromised (CVE-2023-29059) | FortiGuard Labs www.fortinet.com
text/html
URL Logo MISC www.fortinet.com/blog/threat-research/3cx-desktop-app-compromised
CrowdStrike Prevents 3CXDesktopApp Intrusion Campaign www.crowdstrike.com
text/html
URL Logo MISC www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/

Related QID Numbers

  • 378327 3CX Desktop Client Supply Chain Vulnerability

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Application3cx3cx18.11.1213AllAllAll
Application3cx3cx18.12.402AllAllAll
Application3cx3cx18.12.407AllAllAll
Application3cx3cx18.12.407AllAllAll
Application3cx3cx18.12.416AllAllAll
Application3cx3cx18.12.416AllAllAll
  • cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:*:
  • cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:*:
  • cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:*:
  • cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:*:
  • cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:*:
  • cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:windows:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2023-29059 : 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 20… twitter.com/i/web/status/1… 2023-03-30 17:06:30
Twitter Icon @satnam It appears that CVE-2023-29059 was assigned for the supply chain attack involving #3CX desktop apps for Windows and… twitter.com/i/web/status/1… 2023-03-30 18:10:08
Twitter Icon @satnam @likethecoins @Volexity Just saw that a CVE was assigned for this: CVE-2023-29059 2023-03-30 18:11:33
Twitter Icon @satnam @serghei A CVE was assigned for this: CVE-2023-29059 2023-03-30 18:12:22
Reddit Logo Icon /r/netcve CVE-2023-29059 2023-03-30 18:38:49
Reddit Logo Icon /r/MDRsecops 3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer 2023-03-31 15:32:27
Reddit Logo Icon /r/InfoSecNews 3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer 2023-03-31 15:32:07
Reddit Logo Icon /r/hacking 3CX intrusion has been knighted with a CVE of its own (CVE-2023-29059) 2023-03-31 18:36:09
Reddit Logo Icon /r/msp 3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer 2023-03-31 18:14:38
Reddit Logo Icon /r/developers Warning 3CX Users - CVE-2023-29059 (Updated) 2023-04-02 05:22:17
Reddit Logo Icon /r/Hacking_Tutorials Warning 3CX Users - CVE-2023-29059 (Updated) 2023-04-02 05:19:57
Reddit Logo Icon /r/White_Hat_Alliance Warning 3CX Users - CVE-2023-29059 (Updated) 2023-04-02 05:19:16
Reddit Logo Icon /r/hacking Warning 3CX Users - CVE-2023-29059 (Updated) 2023-04-05 00:53:30
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report