All vulnerabilities
CRITICALSupply chainexploited in the wild

CVE-2023-29059

Software vendor · 3CXDesktopApp

Summary

Disclosed in late March 2023, the 3CX DesktopApp VoIP client for Windows and macOS was trojanized via malicious code inserted into 3CX's signed binaries (affected versions include 18.12.407 and 18.12.416). The North Korean Lazarus-linked group abused an old Windows signature-verification flaw (CVE-2013-3900) so malicious DLLs appeared legitimately signed. Mandiant later determined the root cause was a cascading compromise: a 3CX employee had installed a trojanized X_TRADER app from Trading Technologies carrying the VEILEDSIGNAL backdoor, the first publicly documented case of one supply-chain attack enabling another. 3CX had over 600,000 customers and 12 million daily users.

References

Related vulnerabilities

All Supply chain →