Patching Perforce perforations: Critical RCE vulnerability discovered in Perforce Helix Core Server
ID: 9d060651-24d6-5500-ae6f-5bb8f04a8ce3
STIX ID: report--9d060651-24d6-5500-ae6f-5bb8f04a8ce3
Feed Name: Microsoft Security
Threat Score
Microsoft responsibly disclosed four vulnerabilities in Perforce Helix Core Server—most critically an unauthenticated RPC allowing arbitrary command execution as LocalSystem (CVSS 10.0)—and three additional remote denial-of-service flaws; Microsoft found over 1,000 internet-exposed instances, coordinated fixes with Perforce (patch released 2023.1/2513900), and provided mitigation and detection guidance while noting no observed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
