Code Injection Vulnerability in DCE Backup Restoration Process

Code Injection Vulnerability in DCE Backup Restoration Process

CVE-2023-37199 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.

Learn more about our User Device Pen Test.