Vulnerability Details CVE-2023-28122
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.8%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-28122
-
-
cpe:2.3:a:ui:desktop:0.55.1.2
-
cpe:2.3:a:ui:desktop:0.55.3.17
-
cpe:2.3:a:ui:desktop:0.59.1.71