CVE-2023-42523
Description
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WithSecure scanning engine crashes when unpacking a crafted PE file, affecting multiple products.
Vulnerability
A denial-of-service (DoS) vulnerability exists in the scanning engine of certain WithSecure products when processing a malicious Portable Executable (PE) file. The crash occurs during the unpacking phase of the PE file analysis. Affected versions include: WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0, Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
Exploitation
An attacker can remotely trigger the crash by sending a specially crafted PE file to the scanning engine. No authentication or local access is required; the attack can be performed over a network where the scanning service is exposed. The precise sequence involves the attacker delivering the malicious PE file, which the engine then attempts to unpack, leading to a memory corruption or logic error that causes a crash.
Impact
A successful crash denies service to legitimate users and may disrupt automated scanning operations. The impact is a denial-of-service (DoS) condition; no data disclosure, privilege escalation, or code execution is reported.
Mitigation
WithSecure has released security advisories addressing this vulnerability. Affected users should update their products to the latest versions as specified in the advisory [1]. No workarounds are documented; the fix is incorporated into product updates.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- WithSecure/WithSecure productsdescription
- Range: =15
- Range: =15
- Range: >=17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.