CVE-2023-53937
EUVD-2025-20436318.12.2025, 20:15
Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hubstaff | hubstaff | 1.6.13 |
| hubstaff | hubstaff | 1.6.14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration