CVE-2023-53875
HIGHGOM Player 2.3.90.5360 - Remote Code Execution via Internet Explorer Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53875. PoCs published by M. Akil Gündoğan.
AI-analyzed exploit summary This exploit leverages an insecure HTTP connection in GOM Player's IE component to execute remote code via SMB/WebDAV 'search-ms' technique combined with DNS spoofing and a URL+ZIP+VBS MoTW bypass.
Description
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.
Exploits (1)
This exploit leverages an insecure HTTP connection in GOM Player's IE component to execute remote code via SMB/WebDAV 'search-ms' technique combined with DNS spoofing and a URL+ZIP+VBS MoTW bypass.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H