CVE-2023-50443

Encrypted disks created by PRIMX CRYHOD for Windows before Q.2020.4 (ANSSI qualification submission) or CRYHOD for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which disks are opened.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:*
cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:*
cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

20 Dec 2023, 18:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
References () https://www.primx.eu/en/bulletins/security-bulletin-23B3093B/ - () https://www.primx.eu/en/bulletins/security-bulletin-23B3093B/ - Vendor Advisory
References () https://www.primx.eu/fr/blog/ - () https://www.primx.eu/fr/blog/ - Product
Summary
  • (es) Un atacante no autenticado puede modificar los discos cifrados creados por PRIMX CRYHOD para Windows antes de Q.2020.4 (envío de calificación ANSSI) o CRYHOD para Windows antes de 2023.5 para incluir una referencia UNC que pueda activar el tráfico de red saliente desde las maquinas en las que se abren los discos.
First Time Primx
Primx cryhod
Microsoft windows
Microsoft
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:primx:cryhod:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

13 Dec 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-13 21:15

Updated : 2023-12-20 18:51


NVD link : CVE-2023-50443

Mitre link : CVE-2023-50443

CVE.ORG link : CVE-2023-50443


JSON object : View

Products Affected

primx

  • cryhod

microsoft

  • windows