CVE-2023-28144: Kdab Hotspot

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls.

Affected products

  • Kdab Hotspot: from 1.3.0, up to and including 1.4.1

Published 2023-03-14. Last modified 2026-06-17.