HIGH
An issue was discovered in YSoft SAFEQ 6 before 6.0.72
Published Sep 6, 2022
7.8
HIGHCVSS 3.1
EPSS 0.39%
Description
An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer package for the Client V3 services, allowing for local user privilege escalation by overwriting the executable file via an alternative data stream. NOTE: this is not the same as CVE-2021-31859.
Affected products
No data.
OR
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40772 Advisory
- https://www.ysoft.com/en/legal/ysoft-safeq-client-v3-local-privilege-escalation x_refsource_MISCVendor Advisory
- https://ysoft.com x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40772 | Advisory | |
| https://www.ysoft.com/en/legal/ysoft-safeq-client-v3-local-privilege-escalation | x_refsource_MISCVendor Advisory | |
| https://ysoft.com | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 6, 2022
Updated Aug 3, 2024
Reserved Aug 12, 2022
Link CVE-2022-38176
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data