PT-2022-5833 · Unknown · Content Transfer

Tomohisa Hasegawa

·

Published

2022-10-11

·

Updated

2023-08-08

·

CVE-2022-41796

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Content Transfer (for Windows) versions 1.3 and prior
Description The issue is related to an untrusted search path vulnerability in the installer. This could allow an attacker to elevate privileges by using a specially crafted DLL. The vulnerability can be exploited via a Trojan horse DLL in an unspecified directory.
Recommendations For versions 1.3 and prior, consider restricting access to the installer until a patch is available. As a temporary workaround, avoid using the installer in environments where untrusted DLLs could be loaded, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-07245
CVE-2022-41796

Affected Products

Content Transfer