#VU74003 OS Command Injection in Emacs - CVE-2023-27985
Published: March 24, 2023 / Updated: June 19, 2023
Emacs
GNU
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing data passed via the mailto: URI. A remote attacker can trick the victim to click on a specially crafted link and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.