CVE-2023-53954

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious ActSrvNT.exe executable to gain elevated system access when the service restarts.
Configurations

No configuration.

History

19 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-19 21:15

Updated : 2025-12-23 14:52


NVD link : CVE-2023-53954

Mitre link : CVE-2023-53954

CVE.ORG link : CVE-2023-53954


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element