Impact
A remote attacker with network access to port 4307/TCP can upload a specially crafted script to TrueConf Server and cause the isolated environment to break out, allowing arbitrary code execution on the host machine. This vulnerability is a classic code‑execution flaw (CWE-94) that permits an attacker to run native commands with the privileges of the server process.
Affected Systems
The affected product is TrueConf Server from TrueConf. Versions vulnerable include 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and any prior releases before the listed patch versions.
Risk and Exploitability
The CVSS score of 9.5 indicates critical severity. The EPSS score of 0.34% indicates a low but non‑zero exploitation probability. The vulnerability is listed in the CISA KEV catalog, underscoring its potential for exploitation. The attack vector is remote over the network, requiring access to port 4307/TCP; once access is achieved, an attacker can transmit a crafted script that causes the isolated environment to break out, enabling arbitrary code execution on the host with the privileges of the TrueConf server process.
OpenCVE Enrichment