PT-2022-18268 · Revoworks · Revoworks Browser+2

Published

2022-06-14

·

Updated

2022-06-27

·

CVE-2022-27176

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RevoWorks SCVX versions 1.043 and prior RevoWorks Browser versions 2.2.67 and prior RevoWorks Desktop versions 2.1.84 and prior
Description The issue is related to incomplete filtering of special elements, which may allow an attacker to execute a malicious macro. This can be achieved by having a user download, import, and open a specially crafted file in the local environment. The vulnerability exists when using the 'File Sanitization Library' in RevoWorks SCVX, or the 'File Sanitization Option' in RevoWorks Browser and RevoWorks Desktop.
Recommendations For RevoWorks SCVX versions 1.043 and prior, consider disabling the 'File Sanitization Library' until a patch is available. For RevoWorks Browser versions 2.2.67 and prior, restrict the use of the 'File Sanitization Option' to minimize the risk of exploitation. For RevoWorks Desktop versions 2.1.84 and prior, avoid using the 'File Sanitization Option' in the affected environment until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-27176

Affected Products

Revoworks Browser
Revoworks Desktop
Revoworks Scvx