Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-01-17T21:47:04.078Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-25953

Updated: 2024-08-02T11:39:06.539Z

Status : Modified
Published: 2023-05-23T02:15:09.317
Modified: 2025-01-17T22:15:27.970
Link: CVE-2023-25953

No data.