PT-2022-21988 · Unknown · Dr-Web-Engine

Published

2022-06-24

·

Updated

2022-07-05

·

CVE-2022-34053

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DR-Web-Engine version 0.2.0b0
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges via a code execution backdoor in the request package.
Recommendations For version 0.2.0b0, consider removing or avoiding the use of the DR-Web-Engine package until a secure version is available. As a temporary workaround, restrict access to sensitive information and digital currency keys to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-34053

Affected Products

Dr-Web-Engine