CVE-2023-2331

HIGH

42Gears Surelock <2.40.0 - Code Injection

Title source: llm
STIX 2.1

Description

Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 through 2.40.0.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
42gears/surelock 2.3.12 - 2.41.0
Published Apr 27, 2023
Tracked Since Feb 18, 2026