High severity7.8NVD Advisory· Published Nov 30, 2023· Updated Jun 17, 2026
CVE-2023-47454
CVE-2023-47454
Description
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
Affected products
3cpe:2.3:a:netease:cloudmusic:2.10.4:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:netease:cloudmusic:2.10.4:*:*:*:*:windows:*:*
- (no CPE)range: = 2.10.4
- NetEase/CloudMusicdescription
Patches
Vulnerability mechanics
References
1- github.com/xieqiang11/poc-3/tree/mainnvdExploit
News mentions
0No linked articles in our index yet.