CRITICAL🇵🇱 Wersja polska

CVE-2024-23168

CVSS 9.8v3.1pub. 2024-08-15upd. 2026-04-15

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

🤖 AI Analysis
How it works

XSOverlay exposes a local WebSocket API for communication with the application. The flaw lies in the lack of proper source verification for incoming connections (CWE-1385 — Missing Origin Validation in WebSockets), allowing external, non-local websites to connect to this API. An attacker can thus send malicious commands directly to the application running on the user's computer, leading to arbitrary code execution.

Impact

An attacker gains the ability to execute arbitrary code on the victim's device, which may result in complete system compromise, data theft, or installation of malicious software.

Mitigation & patch

XSOverlay should be updated to build 647 or newer. Details are available in the vendor's official references and in the announcement on the Steam platform.

Who is affected

XSOverlay by Xiexe in all versions before build 647

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References