PT-2022-19239 · Microsoft · Link To Windows Service
Rahul Kankrale
·
Published
2022-05-03
·
Updated
2022-05-11
·
CVE-2022-28790
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Link to Windows Service versions prior to 2.3.04.1
Description
The issue is related to improper authentication in the Link to Windows Service, which allows an attacker to lock the device. The patch for this issue adds proper caller signature check logic.
Recommendations
For versions prior to 2.3.04.1, update to version 2.3.04.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Link to Windows Service to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Link To Windows Service