11 August 2026

KLCERT-26-058: TrueConf Server. Breakout from isolated environment

Vendor

TrueConf

Researcher

Vyacheslav KopeytsevPrincipal Security Researcher

Timeline

Timeline

  • Kaspersky ICS CERT advisory published

    07 August 2026

  • Vendor Informing

    August 2026

Description

An unauthorized remote attacker with network access via port 4307/TCP to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, as well as all versions before 5.3, could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.


Exploitability

Remotely

Attack complexity

High (it may take several attempts to successfully exploit the vulnerability)

Privilege required

None

User interaction

None

Confidentiality

High

Integrity

High

Availability

High

Impact

Successful exploitation of this vulnerability could enable an attacker with network access to the vulnerable TrueConf server to execute arbitrary code on the host system.

Affected products

TrueConf Server (for Windows and Linux):

  • All versions before 5.3
  • 5.3.X before 5.3.9
  • 5.4.X before 5.4.9
  • 5.5.X before 5.5.5

Mitigation

  • Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.
  • Perform a full check with antivirus software that has up-to-date antivirus databases and modules.
  • Conduct a scan for indicators of compromise specified in the threat alert “Head Mare APT group exploits vulnerabilities in TrueConf server to deliver PhantomCore malware to conference participants”. In the event that any indicators of compromise are detected, change the passwords for all potentially affected accounts and contact us at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.

Timeline

  • Kaspersky ICS CERT advisory published

    07 August 2026

  • Vendor Informing

    August 2026