CVE-2023-47454: Netease Cloudmusic

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.

Affected products

  • Netease Cloudmusic: version 2.10.4 only

Published 2023-11-30. Last modified 2026-06-17.