PT-2022-5833 · Unknown · Content Transfer
Tomohisa Hasegawa
·
Published
2022-10-11
·
Updated
2023-08-08
·
CVE-2022-41796
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Content Transfer (for Windows) versions 1.3 and prior
Description
The issue is related to an untrusted search path vulnerability in the installer. This could allow an attacker to elevate privileges by using a specially crafted DLL. The vulnerability can be exploited via a Trojan horse DLL in an unspecified directory.
Recommendations
For versions 1.3 and prior, consider restricting access to the installer until a patch is available. As a temporary workaround, avoid using the installer in environments where untrusted DLLs could be loaded, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Content Transfer