QID 378930
Date Published: 2023-12-06
QID 378930: Azure RTOS GUIX Studio Remote Code Execution (RCE) Vulnerability October 2023
Azure RTOS GUIX Studio is a Windows desktop application used to quickly and easily design and layout the user interface to be run by the GUIX library on a wide array of embedded hardware devices.
CVE-2023-36418: Azure RTOS GUIX Studio is vulnerable to Remote Code Execution Vulnerability.
Affected Versions:
Azure RTOS GUIX Studio versions prior to 6.3.0.0
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version by using the following WMI query select version from Win32_InstalledStoreProgram where name='Microsoft.AzureRTOSGUIXStudio'
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary commands on the target system.
Solution
Customers are advised to upgrade latest available version to remediate this vulnerability. For more information please refer to Azure RTOS GUIX Studio Advisory.
Vendor References
- Azure RTOS GUIX Studio -
msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36418
CVEs related to QID 378930
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Azure RTOS GUIX Studio |
|