PT-2025-52529 · Filezilla · Filezilla Client

·

CVE-2023-53959

·

Published

2023-02-14

·

Updated

2025-12-20

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FileZilla Client version 3.63.1
Description The FileZilla Client application is susceptible to a DLL hijacking issue. An attacker can exploit this by placing a specially crafted TextShaping.dll file within the application directory. Successful exploitation allows the attacker to execute malicious code, potentially achieving remote code execution when the application is launched. The attack involves replacing a missing DLL with a malicious payload, which can be generated using tools like msfvenom.
Recommendations Replace the TextShaping.dll file in the FileZilla Client application directory with a legitimate version.

Exploit

Fix

RCE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11041
CVE-2023-53959

Affected Products

Filezilla Client