#VU74002 Code Injection in Emacs - CVE-2023-27986
Published: March 24, 2023 / Updated: June 19, 2023
Emacs
GNU
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when parsing data passed via the mailto: URI. A remote attacker can trick the victim to click on a specially crafted URL and execute arbitrary Emacs Lisp code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.