CVE-2023-29059
3CX 3CXPhone vulnerability analysis and mitigation

Overview

The 3CX DesktopApp through version 18.12.416 was discovered to contain embedded malicious code, which was actively exploited in the wild during March 2023. The vulnerability (CVE-2023-29059) specifically affected versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application (NIST, CrowdStrike).

Technical details

The attack involved a DLL sideloading scenario where the malicious code was embedded in the ffmpeg.dll file, which contained instructions and a payload within another DLL via an encrypted blob (d3dcompiler_47.dll). The malware used a static RC4 encryption key '3jB(2bsG#@c7' to decrypt the payload. The compromised application would attempt to pull ICO files from GitHub containing various URIs for download, where the final payload would be loaded and installed to the target environment. The CVSS v3.1 base score for this vulnerability is 7.8 (HIGH) (FortiGuard Labs, NIST).

Impact

The compromise affected 3CX, a popular VoIP/PBX solutions provider with over 600,000 customers worldwide and 12 million daily users across 190 countries. Organizations in various sectors including automobile, aerospace, finance, food and beverage, government, hospitality, and manufacturing were potentially impacted (FortiGuard Labs).

Mitigation and workarounds

3CX recommended users to uninstall the affected desktop client versions and migrate to their Progressive Web App (PWA) as an immediate mitigation measure. The company revoked the certificate for the previous versions and worked on releasing new versions of the Windows and Mac applications. For Windows users, 3CX issued a new certificate and rebuilt the MSI installers. The company focused on addressing the Windows version first while investigating the broader security breach (3CX Blog).

Community reactions

The security community quickly responded to the incident, with multiple security firms including CrowdStrike, Huntress, and FortiGuard Labs releasing detailed analyses and detection mechanisms. The incident was compared to other significant supply chain attacks such as SolarWinds and Kaseya VSA. The GitHub repository hosting the malicious payloads was taken down after the compromise was discovered, helping to limit the attack's impact (Huntress).

Additional resources


SourceThis report was generated using AI

Related 3CX 3CXPhone vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-49954CRITICAL9.8
  • 3CX 3CXPhone logo3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesDec 25, 2023
CVE-2023-27362HIGH7.8
  • 3CX 3CXPhone logo3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 03, 2024
CVE-2023-29059HIGH7.8
  • 3CX 3CXPhone logo3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMar 30, 2023
CVE-2022-48483HIGH7.5
  • 3CX 3CXPhone logo3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023
CVE-2022-48482HIGH7.5
  • 3CX 3CXPhone logo3CX 3CXPhone
  • cpe:2.3:a:3cx:3cx
NoYesMay 02, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management