CVE-2023-29059
Published on: Not Yet Published
Last Modified on: 04/10/2023 04:29:00 PM UTC
Certain versions of 3cx from 3cx contain the following vulnerability:
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
- CVE-2023-29059 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CWE - CWE-506: Embedded Malicious Code (4.8) | cwe.mitre.org text/html |
![]() |
3CX VoIP Software Compromise & Supply Chain Threats | www.huntress.com text/html |
![]() |
Update 2: 3CX users under DLL-sideloading attack: What you need to know – Sophos News | Exploit Technical Description Third Party Advisory news.sophos.com text/html |
![]() |
3CX Security Alert for Electron Windows App | Desktop App | www.3cx.com text/html |
![]() |
3CX Desktop App Compromised (CVE-2023-29059) | FortiGuard Labs | www.fortinet.com text/html |
![]() |
CrowdStrike Prevents 3CXDesktopApp Intrusion Campaign | www.crowdstrike.com text/html |
![]() |
Related QID Numbers
- 378327 3CX Desktop Client Supply Chain Vulnerability
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | 3cx | 3cx | 18.11.1213 | All | All | All |
Application | 3cx | 3cx | 18.12.402 | All | All | All |
Application | 3cx | 3cx | 18.12.407 | All | All | All |
Application | 3cx | 3cx | 18.12.407 | All | All | All |
Application | 3cx | 3cx | 18.12.416 | All | All | All |
Application | 3cx | 3cx | 18.12.416 | All | All | All |
- cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:*:
- cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:*:
- cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:*:
- cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:*:
- cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:*:
- cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:windows:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-29059 : 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 20… twitter.com/i/web/status/1… | 2023-03-30 17:06:30 |
![]() |
It appears that CVE-2023-29059 was assigned for the supply chain attack involving #3CX desktop apps for Windows and… twitter.com/i/web/status/1… | 2023-03-30 18:10:08 |
![]() |
@likethecoins @Volexity Just saw that a CVE was assigned for this: CVE-2023-29059 | 2023-03-30 18:11:33 |
![]() |
@serghei A CVE was assigned for this: CVE-2023-29059 | 2023-03-30 18:12:22 |
![]() |
CVE-2023-29059 | 2023-03-30 18:38:49 |
![]() |
3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer | 2023-03-31 15:32:27 |
![]() |
3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer | 2023-03-31 15:32:07 |
![]() |
3CX intrusion has been knighted with a CVE of its own (CVE-2023-29059) | 2023-03-31 18:36:09 |
![]() |
3CX Suffers Supply Chain Attack: Electron Windows App Drops an Unknown Infostealer | 2023-03-31 18:14:38 |
![]() |
Warning 3CX Users - CVE-2023-29059 (Updated) | 2023-04-02 05:22:17 |
![]() |
Warning 3CX Users - CVE-2023-29059 (Updated) | 2023-04-02 05:19:57 |
![]() |
Warning 3CX Users - CVE-2023-29059 (Updated) | 2023-04-02 05:19:16 |
![]() |
Warning 3CX Users - CVE-2023-29059 (Updated) | 2023-04-05 00:53:30 |