CVE-2026-72530
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TrueConf | TrueConf Server | * < 5.3 | affected |
| TrueConf | TrueConf Server | 5.3 < 5.3.9 | affected |
| TrueConf | TrueConf Server | 5.4 < 5.4.9 | affected |
| TrueConf | TrueConf Server | 5.5 < 5.5.5 | affected |
Weaknesses
- CWE-94: CWE-94: Code Injection
Workarounds
Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules. Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: active
- Automatable: no
- Technical Impact: total
Additional References
- https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.