CVE-2023-45883: Enghouse Qumu

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

Affected products

  • Enghouse Qumu: from 2.0.0, before 2.0.63 (fixed in 2.0.63)

Published 2023-10-19. Last modified 2026-06-17.