{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-25T23:43:55.716","vulnerabilities":[{"cve":{"id":"CVE-2023-7270","sourceIdentifier":"551230f0-3615-47bd-b7cc-93e92e730bbf","published":"2024-06-27T10:15:10.240","lastModified":"2026-06-17T06:52:26.757","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed.\n\n\n\n\n\nThe SoftMaker Office and FreeOffice MSI installer files were found to\n produce a visible conhost.exe window running as the SYSTEM user when \nusing the repair function of msiexec.exe. This allows a local, \nlow-privileged attacker to use a chain of actions, to open a fully \nfunctional cmd.exe with the privileges of the SYSTEM user."},{"lang":"es","value":"Se descubrió un problema en SoftMaker Office 2024/NX antes de la revisión 1214 y SoftMaker FreeOffice 2014 antes de la revisión 1215. FreeOffice 2021 también se ve afectado, pero no se solucionará. Se descubrió que los archivos de instalación de SoftMaker Office y FreeOffice MSI producían una ventana visible de conhost.exe ejecutándose como el usuario de SYSTEM cuando se utiliza la función de reparación de msiexec.exe.Esto permite a un atacante local con pocos privilegios utilizar una cadena de acciones para abrir un cmd.exe completamente funcional con los privilegios del usuario de SYSTEM."}],"affected":[{"source":"551230f0-3615-47bd-b7cc-93e92e730bbf","affectedData":[{"vendor":"SoftMaker Software GmbH","product":"Office","defaultStatus":"affected","versions":[{"version":"2024 / NX, revision 1214","status":"unaffected"}]},{"vendor":"SoftMaker Software GmbH","product":"FreeOffice","defaultStatus":"affected","versions":[{"version":"2024, revision 1215","status":"unaffected"}]},{"vendor":"SoftMaker Software GmbH","product":"FreeOffice","defaultStatus":"affected","versions":[{"version":"2021 revision 1068","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"softmaker","product":"softmaker_office","defaultStatus":"unknown","cpes":["cpe:2.3:a:softmaker:softmaker_office:2021:*:*:*:*:*:*:*"],"versions":[{"version":"2024","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-23T13:11:41.264519Z","id":"CVE-2023-7270","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]}],"references":[{"url":"http://seclists.org/fulldisclosure/2024/Jul/5","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"https://r.sec-consult.com/softmaker","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"https://softmaker.de/download/servicepacks","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"https://www.freeoffice.com/de/download/servicepacks","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"http://seclists.org/fulldisclosure/2024/Jul/5","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://r.sec-consult.com/softmaker","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://softmaker.de/download/servicepacks","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.freeoffice.com/de/download/servicepacks","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}