PT-2022-7846 · Filezilla · Filezilla Client

Cyril Vallicari

·

Published

2022-07-18

·

Updated

2022-07-25

·

CVE-2016-15003

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FileZilla Client version 3.17.0.0
Description A vulnerability has been found in the Installer component, specifically affecting the file C:Program FilesFileZilla FTP Clientuninstall.exe. The manipulation leads to an unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 3.17.0.0, consider updating to a newer version to mitigate the risk, as the current version is affected by the unquoted search path vulnerability. As a temporary workaround, restrict access to the uninstall.exe file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-15003

Affected Products

Filezilla Client