VYPR
Unrated severityNVD Advisory· Published Nov 16, 2023· Updated Aug 2, 2024

CVE-2023-47263

CVE-2023-47263

Description

Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, WithSecure Linux Security 64 12.0, WithSecure Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 15 and later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial-of-service vulnerability in WithSecure antivirus engine allows remote crash via fuzzed PE32 file, affecting multiple products.

Vulnerability

A denial-of-service (DoS) vulnerability exists in the antivirus engine of multiple WithSecure products when scanning a specially crafted (fuzzed) PE32 file. The affected products include WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, WithSecure Linux Security 64 12.0, WithSecure Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 15 and later [1].

Exploitation

An attacker can trigger the vulnerability remotely by delivering a fuzzed PE32 file to the target system, for example via email attachment or web download. When the WithSecure antivirus engine scans the malicious file, it crashes, causing a denial of service. No authentication or special privileges are required beyond the ability to have the file scanned by the affected product [1].

Impact

Successful exploitation results in a denial of service of the antivirus engine, leaving the system temporarily unprotected until the engine is automatically or manually restarted. No code execution, privilege escalation, or data compromise has been reported [1].

Mitigation

WithSecure has released security updates to address this vulnerability. Affected users should apply the latest updates from WithSecure as detailed in the advisory [1]. No workarounds are documented. As of the publication date, no active exploitation in the wild has been observed [1].

References
  1. CVE-2023-NNN4

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.