CVE-2023-53937

H

ubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hubstaff:hubstaff:1.6.13:*:*:*:*:*:*:*
cpe:2.3:a:hubstaff:hubstaff:1.6.14:*:*:*:*:*:*:*

History

14 Jan 2026, 20:02

Type Values Removed Values Added
CPE cpe:2.3:a:hubstaff:hubstaff:1.6.14:*:*:*:*:*:*:*
cpe:2.3:a:hubstaff:hubstaff:1.6.13:*:*:*:*:*:*:*
References () https://hubstaff.com/ - () https://hubstaff.com/ - Product
References () https://www.exploit-db.com/exploits/51461 - () https://www.exploit-db.com/exploits/51461 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/hubstaff-dll-search-order-hijacking-via-wowlog-library - () https://www.vulncheck.com/advisories/hubstaff-dll-search-order-hijacking-via-wowlog-library - Third Party Advisory
First Time Hubstaff
Hubstaff hubstaff

19 Dec 2025, 18:00

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 20:15

Updated : 2026-01-14 20:02


NVD link : CVE-2023-53937

Mitre link : CVE-2023-53937

CVE.ORG link : CVE-2023-53937


JSON object : View

Products Affected
CWE
CWE-427

Uncontrolled Search Path Element