An issue was discovered in the 3CX Phone System...
Critical severity
Unreviewed
Published
May 7, 2022
to the GitHub Advisory Database
•
Updated May 2, 2023
Description
Published by the National Vulnerability Database
May 6, 2022
Published to the GitHub Advisory Database
May 7, 2022
Last updated
May 2, 2023
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server, leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. Versions prior to version 18, Hotfix 1 Build 18.0.3.461 March 2022, are prone to an additional unauthenticated file system access to C:\Windows\System32.
References