CVE-2023-53959: FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dll
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53959?
CVE-2023-53959 is classified as a high-severity vulnerability due to its potential for executing arbitrary code.
How do I fix CVE-2023-53959?
To fix CVE-2023-53959, update to the latest version of FileZilla Client that addresses this vulnerability.
What type of attack can be executed through CVE-2023-53959?
CVE-2023-53959 allows attackers to execute a DLL hijacking attack, enabling them to run malicious code on the affected system.
Which versions of FileZilla Client are affected by CVE-2023-53959?
CVE-2023-53959 affects FileZilla Client version 3.63.1 and potentially earlier versions.
Can CVE-2023-53959 be exploited remotely?
Yes, CVE-2023-53959 can be exploited remotely by placing a malicious DLL in the application directory.