๐Ÿ” CVE Alert

CVE-2023-53937

HIGH 7.8

Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CWE CWE-427
Vendor hubstaff
Product hubstaff
Published Dec 18, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for hubstaff hubstaff

Be the first to know when new high vulnerabilities affecting hubstaff hubstaff are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Hubstaff / Hubstaff
1.6.13, 1.6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/51461 hubstaff.com: https://hubstaff.com/ vulncheck.com: https://www.vulncheck.com/advisories/hubstaff-dll-search-order-hijacking-via-wowlog-library

Credits

Ahsan Azad