# CVE-2023-5834

## Summary

- **CVE ID:** CVE-2023-5834
- **Severity:** LOW
- **CVSS Score:** 3.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N)
- **CWE:** CWE-1386
- **Published:** Oct 27, 2023
- **Last Modified:** Mar 13, 2026

## Description

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.

## Affected Products

- HashiCorp — Vagrant (*)

## References

- [CNA](https://discuss.hashicorp.com/t/hcsec-2023-31-vagrant-s-windows-installer-allowed-directory-junction-write/59568)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.08%
- **EPSS Percentile:** 24.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._