PT-2022-22402 · Microsoft · Windows

Published

2022-07-20

·

Updated

2022-08-01

·

CVE-2022-34866

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Passage Drive versions v1.4.0 to v1.5.1.0 Passage Drive for Box version v1.0.0
Description The issue is related to insufficient data verification for interprocess communication, which can be exploited by running a malicious program. This exploitation can lead to the execution of an arbitrary OS command with LocalSystem privilege of the Windows system where the product is running.
Recommendations For Passage Drive versions v1.4.0 to v1.5.1.0, consider disabling interprocess communication functionality until a patch is available. For Passage Drive for Box version v1.0.0, restrict the use of the vulnerable component to minimize the risk of exploitation. As a temporary workaround, avoid running untrusted programs on the Windows system where the product is installed.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-34866

Affected Products

Windows