Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup. | |
| Title | Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T20:22:50.285Z
Reserved: 2025-12-16T19:22:09.997Z
Link: CVE-2023-53937
Updated: 2025-12-18T20:22:29.933Z
Status : Received
Published: 2025-12-18T20:15:52.000
Modified: 2025-12-18T20:15:52.000
Link: CVE-2023-53937
No data.
OpenCVE Enrichment
No data.