cwe.mitre.org
https://cwe.mitre.org/data/definitions/506.html CVE-2023-29059
HIGH
3CX DesktopApp through 18.12.416 Embedded Malicious Code
Record summary
CVE-2023-29059 has a selected CVSS score of 7.8 (high).
Description
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 29, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
7news.sophos.com
https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-29059 3cx.com
https://www.3cx.com/blog/news/desktopapp-security-alert crowdstrike.com
https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers fortinet.com
https://www.fortinet.com/blog/threat-research/3cx-desktop-app-compromised huntress.com
https://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats