Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-26526

Опубликовано: 17 мар. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that directory. (This problem can only happen in a non-default installation. The person who installs the product must specify that it is being installed for all users. Also, the person who installs the product must specify that the system PATH should be changed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:anaconda:anaconda3:*:*:*:*:*:*:*:*
Версия до 2021.11.0.0 (включая)
cpe:2.3:a:conda:miniconda3:*:*:*:*:*:*:*:*
Версия до 4.11.0.0 (включая)

EPSS

Процентиль: 34%
0.00135
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
github
почти 4 года назад

Anaconda Anaconda3 through 2021.11.0.0 and Miniconda3 through 11.0.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that directory. (This problem can only happen in a non-default installation. The person who installs the product must specify that it is being installed for all users. Also, the person who installs the product must specify that the system PATH should be changed.)

EPSS

Процентиль: 34%
0.00135
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732