logo

Patching Perforce perforations: Critical RCE vulnerability discovered in Perforce Helix Core Server

ID: 9d060651-24d6-5500-ae6f-5bb8f04a8ce3

STIX ID: report--9d060651-24d6-5500-ae6f-5bb8f04a8ce3

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2023-12-15

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft responsibly disclosed four vulnerabilities in Perforce Helix Core Server—most critically an unauthenticated RPC allowing arbitrary command execution as LocalSystem (CVSS 10.0)—and three additional remote denial-of-service flaws; Microsoft found over 1,000 internet-exposed instances, coordinated fixes with Perforce (patch released 2023.1/2513900), and provided mitigation and detection guidance while noting no observed in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.