PT-2022-18268 · Revoworks · Revoworks Browser+2
Published
2022-06-14
·
Updated
2022-06-27
·
CVE-2022-27176
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RevoWorks SCVX versions 1.043 and prior
RevoWorks Browser versions 2.2.67 and prior
RevoWorks Desktop versions 2.1.84 and prior
Description
The issue is related to incomplete filtering of special elements, which may allow an attacker to execute a malicious macro. This can be achieved by having a user download, import, and open a specially crafted file in the local environment. The vulnerability exists when using the 'File Sanitization Library' in RevoWorks SCVX, or the 'File Sanitization Option' in RevoWorks Browser and RevoWorks Desktop.
Recommendations
For RevoWorks SCVX versions 1.043 and prior, consider disabling the 'File Sanitization Library' until a patch is available.
For RevoWorks Browser versions 2.2.67 and prior, restrict the use of the 'File Sanitization Option' to minimize the risk of exploitation.
For RevoWorks Desktop versions 2.1.84 and prior, avoid using the 'File Sanitization Option' in the affected environment until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Revoworks Browser
Revoworks Desktop
Revoworks Scvx