CVE-2023-35863: Madefornet HTTP Debugger
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.
Affected products
- Madefornet HTTP Debugger: up to and including 9.12
Published 2023-07-05. Last modified 2026-06-17.