CVE-2023-0104

Description

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  

Remediation

Solution:

  • Weintek recommends users to implement the following mitigation techniques:·         Upgrade EasyBuilder Pro to v6.07.02.480 https://dl.weintek.com/EBPro/Installer/EBproV60702480.zip , v6.08.01.350 https://dl.weintek.com/EBPro/Installer/EBproV60801350.zip or later. ·         Use Decompile only on trusted sources and only when needed.

Categories

9.3
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 3.20% Top 15%
Third-Party Advisory cisa.gov
Affected: Weintek EasyBuilder Pro cMT
Published at:
Updated at:

References

Link Tags
https://www.cisa.gov/uscert/ics/advisories/icsa-23-045-01 third party advisory us government resource

Frequently Asked Questions

What is the severity of CVE-2023-0104?
CVE-2023-0104 has been scored as a critical severity vulnerability.
How to fix CVE-2023-0104?
To fix CVE-2023-0104: Weintek recommends users to implement the following mitigation techniques:·         Upgrade EasyBuilder Pro to v6.07.02.480 https://dl.weintek.com/EBPro/Installer/EBproV60702480.zip , v6.08.01.350 https://dl.weintek.com/EBPro/Installer/EBproV60801350.zip or later. ·         Use Decompile only on trusted sources and only when needed.
Is CVE-2023-0104 being actively exploited in the wild?
It is possible that CVE-2023-0104 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~3% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-0104?
CVE-2023-0104 affects Weintek EasyBuilder Pro cMT .
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.