
Cloud Vulnerability DB
A community-led vulnerabilities database
The 3CX DesktopApp through version 18.12.416 was discovered to contain embedded malicious code, which was actively exploited in the wild during March 2023. The vulnerability (CVE-2023-29059) specifically affected versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application (NIST, CrowdStrike).
The attack involved a DLL sideloading scenario where the malicious code was embedded in the ffmpeg.dll file, which contained instructions and a payload within another DLL via an encrypted blob (d3dcompiler_47.dll). The malware used a static RC4 encryption key '3jB(2bsG#@c7' to decrypt the payload. The compromised application would attempt to pull ICO files from GitHub containing various URIs for download, where the final payload would be loaded and installed to the target environment. The CVSS v3.1 base score for this vulnerability is 7.8 (HIGH) (FortiGuard Labs, NIST).
The compromise affected 3CX, a popular VoIP/PBX solutions provider with over 600,000 customers worldwide and 12 million daily users across 190 countries. Organizations in various sectors including automobile, aerospace, finance, food and beverage, government, hospitality, and manufacturing were potentially impacted (FortiGuard Labs).
3CX recommended users to uninstall the affected desktop client versions and migrate to their Progressive Web App (PWA) as an immediate mitigation measure. The company revoked the certificate for the previous versions and worked on releasing new versions of the Windows and Mac applications. For Windows users, 3CX issued a new certificate and rebuilt the MSI installers. The company focused on addressing the Windows version first while investigating the broader security breach (3CX Blog).
The security community quickly responded to the incident, with multiple security firms including CrowdStrike, Huntress, and FortiGuard Labs releasing detailed analyses and detection mechanisms. The incident was compared to other significant supply chain attacks such as SolarWinds and Kaseya VSA. The GitHub repository hosting the malicious payloads was taken down after the compromise was discovered, helping to limit the attack's impact (Huntress).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."