CVE-2026-72530

Summary

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Affected Software

VendorProductVersion RangeStatus
TrueConfTrueConf Server* < 5.3affected
TrueConfTrueConf Server5.3 < 5.3.9affected
TrueConfTrueConf Server5.4 < 5.4.9affected
TrueConfTrueConf Server5.5 < 5.5.5affected

Weaknesses

  • CWE-94: CWE-94: Code Injection

Workarounds

Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules. Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

Additional References

References