PT-2022-22402 · Microsoft · Windows
Published
2022-07-20
·
Updated
2022-08-01
·
CVE-2022-34866
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Passage Drive versions v1.4.0 to v1.5.1.0
Passage Drive for Box version v1.0.0
Description
The issue is related to insufficient data verification for interprocess communication, which can be exploited by running a malicious program. This exploitation can lead to the execution of an arbitrary OS command with LocalSystem privilege of the Windows system where the product is running.
Recommendations
For Passage Drive versions v1.4.0 to v1.5.1.0, consider disabling interprocess communication functionality until a patch is available.
For Passage Drive for Box version v1.0.0, restrict the use of the vulnerable component to minimize the risk of exploitation.
As a temporary workaround, avoid running untrusted programs on the Windows system where the product is installed.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows