← Retour aux CVEs
CVE-2022-28792
MEDIUM6.2
Description
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.
Details CVE
Score CVSS v3.16.2
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie5/3/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
samsung:gear_iconx_pc_manager
Faiblesses (CWE)
CWE-427CWE-427
References
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=5(mobile.security@samsung.com)
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=5(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.