PT-2026-96311 · Unknown · Desktopsms
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
DesktopSMS version 1.11.0
Description
An unauthorized access issue exists in the application's local service. Local attackers can interact with this unauthenticated service via same-device loopback to perform privileged SMS operations using the application's permissions. This allows for the transmission of SMS, retrieval of SMS-derived content, and the persistence of an attacker-selected paired identity without requiring user interaction or pairing confirmation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Desktopsms