PT-2022-19567 · Apache Friends · Xampp

Published

2022-05-23

·

Updated

2022-06-07

·

CVE-2022-29376

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xampp for Windows versions 8.1.4 and below
Description The issue is related to insecure permissions for the install directory, allowing attackers to execute arbitrary code by overwriting binaries in the directory.
Recommendations For versions 8.1.4 and below, consider changing the permissions of the install directory to prevent unauthorized access until a patch is available. As a temporary workaround, restrict write access to the install directory to minimize the risk of exploitation. Avoid using the vulnerable directory for executing binaries until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29376

Affected Products

Xampp