Vulnerability Details CVE-2023-29059
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.9%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-29059
-
3cx
»
3cx
»
Version: 18.11.1213
cpe:2.3:a:3cx:3cx:18.11.1213
-
3cx
»
3cx
»
Version: 18.12.402
cpe:2.3:a:3cx:3cx:18.12.402
-
3cx
»
3cx
»
Version: 18.12.407
cpe:2.3:a:3cx:3cx:18.12.407
-
3cx
»
3cx
»
Version: 18.12.416
cpe:2.3:a:3cx:3cx:18.12.416