Attacker-selected QRC resource opening via crafted hyperlink
Published Jul 14, 2023 · Updated Oct 22, 2024
Improper hyperlink validation in Savoir-faire Linux Jami 20222284 on Windows allows remote attackers to invoke a QRC URL through a message. The message hyperlink handler renders a custom HTML anchor as a normal link, then passes its unvalidated href string to Windows, which resolves it under qrc:/components/. A recipient must click the crafted link; the demonstrated result is an attempt to open an attacker-selected internal QRC resource, not established arbitrary code execution.
Summary
What happened
Improper hyperlink validation in Savoir-faire Linux Jami 20222284 on Windows allows remote attackers to invoke a QRC URL through a message. The message hyperlink handler renders a custom HTML anchor as a normal link, then passes its unvalidated href string to Windows, which resolves it under qrc:/components/. A recipient must click the crafted link; the demonstrated result is an attempt to open an attacker-selected internal QRC resource, not established arbitrary code execution.
The record
- CVE
- CVE-2023-3434
- Published
- Jul 14, 2023
- Updated
- Oct 22, 2024
- Vendor
- Savoir-faire Linux
- Product
- Jami
- Classifications
- CWE-20, CAPEC-48, T1204.001
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jul 14, 2023CVE publishedPublication date reported by the CVE source.
- Oct 22, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=20222284
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Crafted HTML anchor QRC demonstrationproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo