CVE-2023-6235

HIGH

Duet Display <2.5.9.1 - Code Injection

Title source: llm
STIX 2.1

Description

An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution and persistence of arbitrary code.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
duetdisplay/duet_display 2.5.9.1
Published Nov 21, 2023
Tracked Since Feb 18, 2026