CVE-2023-7270

MEDIUM

SoftMaker Office/FreOffice <1214 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.

References (4)

Core 4
Core References
Various Sources exploit third-party-advisory
https://r.sec-consult.com/softmaker

Scores

CVSS v3 5.3
EPSS 0.0032
EPSS Percentile 23.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (3)
SoftMaker Software GmbH/FreeOffice 2021 revision 1068
SoftMaker Software GmbH/FreeOffice 2024, revision 1215
SoftMaker Software GmbH/Office 2024 / NX, revision 1214
Published Jun 27, 2024
Tracked Since Feb 18, 2026