CVE-2026-30284

8.6

UXGROUP LLC · Voice Recorder

UXGROUP LLC Voice Recorder v10.0 contains an arbitrary file overwrite vulnerability during the file import process, which can lead to arbitrary code execution or unauthorized information exposure.

Executive summary

A high-severity arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 poses a significant risk of remote code execution and system compromise.

Vulnerability

This is an arbitrary file overwrite vulnerability triggered during the file import process. Based on the CVSS vector (AV:L/PR:N/UI:R), the flaw requires user interaction and local access to initiate the malicious import.

Business impact

The vulnerability allows an attacker to overwrite critical internal system files. This can result in full system compromise, the execution of arbitrary code, or the exposure of sensitive data, justifying the high CVSS score of 8.6. Organizations relying on this software face potential data breaches and significant service disruption if the application is exploited to gain elevated control over the host environment.

Remediation

Immediate Action: Since no official patch is currently identified, restrict access to the file import functionality and monitor the application for suspicious file operations.

Proactive Monitoring: Review system access logs for unusual file write operations, particularly those originating from the application directory or involving system-critical files.

Compensating Controls: Implement file system auditing to detect unauthorized modification of sensitive configuration files and restrict the application's service account permissions to the minimum necessary level.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, attributed to the research findings documented in the GitHub issue linked by the CVE record.

Analyst recommendation

Given the potential for code execution and the presence of a public proof-of-concept, users must exercise extreme caution when importing files into the application. If the software is non-essential, consider disabling it until the vendor releases a security update. Administrators should prioritize monitoring and least-privilege configurations to mitigate the impact of this flaw until a formal patch is available.

Sources