CVE-2023-53937: Hubstaff
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.
Affected products
- Hubstaff Hubstaff: version 1.6.13 only; version 1.6.14 only
Published 2025-12-18. Last modified 2026-06-17.