{"id":"CVE-2023-53937","title":"Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library","summary":"Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the syste…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-427"],"vendor":"Hubstaff","product":"Hubstaff","affected":["Hubstaff 1.6.13, 1.6.14"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2025-12-18T20:21:10.894554Z"},"exploitAvailable":true,"published":"2025-12-18","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:43.302Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2023-53937","references":[{"url":"https://www.exploit-db.com/exploits/51461","label":"ExploitDB-51461"},{"url":"https://hubstaff.com/","label":"Official Product Homepage"},{"url":"https://www.vulncheck.com/advisories/hubstaff-dll-search-order-hijacking-via-wowlog-library","label":"VulnCheck Advisory: Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library"}],"tags":["cve.org","exploit-available"],"epss":0.00224,"epssPercentile":0.11801,"ingestedAt":"2026-10-01T15:48:17.872Z","slug":"CVE-2023-53937","body":"## Overview\n\nHubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.\n\n## Affected\n\n- `Hubstaff 1.6.13, 1.6.14`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}