CVE-2023-53965

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sound4:impact_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:impact:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sound4:pulse_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:pulse:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sound4:first_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:first:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sound4:impact_eco_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:impact_eco:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sound4:pulse_eco_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:pulse_eco:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sound4:big_voice_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:big_voice:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sound4:voice_ula2_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:voice_ula2:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sound4:voice_ula4_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:voice_ula4:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sound4:voice_ula8_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:voice_ula8:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:sound4:ip_connect_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:ip_connect:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:sound4:wm2_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:wm2:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:sound4:stream_x2_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:stream_x2:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:sound4:stream_x4_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:stream_x4:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:sound4:stream_x8_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:stream_x8:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:sound4:playout_ula8_firmware:4.1.102:*:*:*:*:*:*:*
cpe:2.3:h:sound4:playout_ula8:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-22 22:16

Updated : 2026-01-29 16:11


NVD link : CVE-2023-53965

Mitre link : CVE-2023-53965

CVE.ORG link : CVE-2023-53965


JSON object : View

Products Affected

sound4

  • voice_ula2_firmware
  • big_voice_firmware
  • voice_ula4
  • impact_eco_firmware
  • stream_x8_firmware
  • pulse
  • voice_ula8
  • stream_x4_firmware
  • ip_connect
  • impact_eco
  • voice_ula2
  • playout_ula8
  • stream_x4
  • pulse_firmware
  • impact_firmware
  • first_firmware
  • impact
  • stream_x2_firmware
  • stream_x8
  • voice_ula4_firmware
  • playout_ula8_firmware
  • voice_ula8_firmware
  • wm2
  • stream_x2
  • big_voice
  • pulse_eco_firmware
  • wm2_firmware
  • first
  • ip_connect_firmware
  • pulse_eco
CWE
CWE-428

Unquoted Search Path or Element