PT-2022-15308 · Asus · Rog Live Service
Quella Cosima
·
Published
2022-03-01
·
Updated
2022-03-08
·
CVE-2022-22262
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ROG Live Service (affected versions not specified)
Description
The issue arises from an improper link resolution before file access in ROG Live Service's function for deleting temporary files created by installation. This function fails to validate the path before deletion, allowing an unauthenticated local attacker to create an unexpected symbolic link to a system file path. As a result, the attacker can delete arbitrary system files and disrupt system services.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rog Live Service