CVE-2023-43765
Description
Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A denial-of-service vulnerability exists in WithSecure products' aeelf component allowing memory corruption via scanning a crafted document file.
Vulnerability
The vulnerability resides in the aeelf component of multiple WithSecure security products. It allows a denial-of-service (DoS) attack by causing a crash when scanning a specially crafted document file. Affected versions include: WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0, Linux Protection 12.0, and WithSecure Atlant 1.0.35-1 [1].
Exploitation
An attacker can trigger the vulnerability by providing a malicious document file to be scanned by the affected product. The attack vector is local or remote depending on the product deployment (e.g., a file delivered via email or web download). No authentication is required if the scanning occurs automatically; user interaction is limited to the victim opening or receiving the file.
Impact
Successful exploitation results in a crash of the aeelf component, causing a denial of service. The attacker can cause the security product to fail, potentially leaving the system unprotected temporarily until the service is restarted. There is no evidence of code execution or privilege escalation.
Mitigation
WithSecure has released security advisories; users should update to fixed versions as per vendor guidance [1]. For specific version fix details, refer to WithSecure's official advisory. No workaround is documented. The vulnerability is not listed in CISA KEV as of September 2023.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- WithSecure/WithSecure Client Securitydescription
- Range: = 1.0.35-1
- Range: = 12.0
- Range: = 15
- Range: = 12.0
- Range: = 15
- Range: = 15
- Range: = 15
- Range: >= 17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.