CVE-2023-31747 – Filmora 12 version ( Build 1.0.0.7) - Unquoted Service Paths Privilege Escalation
https://notcve.org/view.php?id=CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges. Filmora version 12 Build 1.0.0.7 suffers from an unquoted service path vulnerability. • https://www.exploit-db.com/exploits/51483 https://github.com/msd0pe-1/CVE-2023-31747 http://filmora.com http://wondershare.com https://packetstormsecurity.com/files/172464/Filmora-12-Build-1.0.0.7-Unquoted-Service-Path.html • CWE-428: Unquoted Search Path or Element •
CVE-2023-27760
https://notcve.org/view.php?id=CVE-2023-27760
An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe. • https://github.com/liong007/Wondershare/issues/9 • CWE-426: Untrusted Search Path •