Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22521

Опубликовано: 27 апр. 2022
Источник: nvd
CVSS3: 7.3
CVSS2: 6.9
EPSS Низкий

Описание

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:miele:benchmark_programming_tool:*:*:*:*:*:*:*:*
Версия до 1.2.72 (исключая)

EPSS

Процентиль: 32%
0.00123
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-732
CWE-732

Связанные уязвимости

CVSS3: 7.3
github
почти 4 года назад

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed by users with administrative privileges. An attacker could thereby obtain higher permissions. The attacker must already have access to the corresponding local system to be able to exchange the files.

EPSS

Процентиль: 32%
0.00123
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-732
CWE-732