CVE-2023-53959: Filezilla-Project Filezilla Client
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
Affected products
- Filezilla-Project Filezilla Client: version 3.63.1 only
Published 2025-12-19. Last modified 2026-06-17.